BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

CISA Adds Two Actively Exploited N-able Flaws to KEV Catalog

CISA Flags Critical N-able N-central Vulnerabilities, Mandates Urgent Patch for Federal Agencies Amid Active Exploitation

  • CISA has added two newly exploited vulnerabilities in N-able N-central to its Known Exploited Vulnerabilities catalog.
  • The vulnerabilities, CVE-2025-8875 and CVE-2025-8876, have been actively exploited and impact remote monitoring software used by managed service providers.
  • N-able released security patches in versions 2025.3.1 and 2024.6 HF2 to fix these issues on August 13, 2025.
  • U.S. federal agencies must apply patches by August 20, 2025, in response to active exploitation risks.
  • CISA also flagged two older Microsoft vulnerabilities, urging updates or discontinuation for unsupported products by September 9, 2025.

The Cybersecurity and Infrastructure Security Agency (CISA) announced on August 14, 2025, that it added two critical security vulnerabilities affecting the N-able N-central platform to its Known Exploited Vulnerabilities (KEV) catalog due to evidence of active exploitation. The vulnerabilities impact N-able N-central, a remote monitoring and management platform widely used by managed service providers to oversee client networks and computers.

- Advertisement -

The two flaws—CVE-2025-8875, which enables command execution through insecure deserialization, and CVE-2025-8876, which is a command injection risk caused by insufficient sanitization of user inputs—were addressed in versions 2025.3.1 and 2024.6 HF2 released on August 13. N-able urges all customers, especially those with administrative accounts, to enable multi-factor authentication and upgrade to the latest software release.

N-able stated: “These vulnerabilities require authentication to exploit. However, there is a potential risk to the security of your N-central environment, if unpatched. You must upgrade your on-premises N-central to 2025.3.1.” The scale and method of the active exploitation are not yet known. CISA is advising all Federal Civilian Executive Branch (FCEB) agencies to apply the required patches by August 20, 2025, to mitigate potential threats.

In addition, on August 13, CISA included two older Microsoft vulnerabilities in its KEV catalog. These include CVE-2013-3893, a memory corruption issue in Internet Explorer allowing remote code execution, and CVE-2007-0671, a remote code execution vulnerability in Microsoft Office Excel. Updates must be applied or unsupported products like Internet Explorer discontinued by September 9, 2025.

At this time, the specific exploitation techniques for the N-central vulnerabilities have not been publicly disclosed. The situation remains under review as agencies and organizations work to implement the designated protections.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

GTA V mod adds 235 simulated Flock cameras to track players

Modder WTTDOTM has added 235 simulated Flock surveillance cameras to Grand Theft Auto V.The...

Tom Lee: Inflation Less Severe; Bullish on Ethereum

Tom Lee argues portfolio fees and flash memory prices distort inflation metrics, making the...

PayPal CEO rejects $50B buyout, charts an independent future

Paypal CEO Enrique Lores has rejected a buyout offer exceeding $50 billion from rival...

Bitcoin Suisse to shift up to half of its Swiss jobs abroad.

Bitcoin Suisse plans to relocate up to 60 of its 120 Swiss positions, primarily...

OpenAI Asks Congress if AI Rivals Can Legally Slow Development

OpenAI has asked lawmakers whether rival AI developers could legally coordinate a slowdown, according...

Must Read

Symbiosis Crypto Bridge: Your Guide to Moving Assets Between Blockchains

What is a Cross-Chain Crypto Bridge?Why Choose Symbiosis for Your Cross-Chain Needs?Support for 50+ BlockchainsAutomatic Routing for the Best RatesNo Need for RegistrationDirect Wallet...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading