N Able
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any N Able product.
RSS Feeds for N Able security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in N Able products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by N Able Sorted by Most Security Vulnerabilities since 2018
Known Exploited N Able Vulnerabilities
The following N Able vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability |
N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass. CVE-2026-18556 |
August 4, 2026 |
| N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability |
N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556. CVE-2026-18577 |
August 3, 2026 |
| N-able N-Central Command Injection Vulnerability |
N-able N-Central contains a command injection vulnerability via improper sanitization of user input. CVE-2025-8876 Exploit Probability: 3.1% |
August 13, 2025 |
| N-able N-Central Insecure Deserialization Vulnerability |
N-able N-Central contains an insecure deserialization vulnerability that could lead to command execution. CVE-2025-8875 Exploit Probability: 1.6% |
August 13, 2025 |
By the Year
In 2026 there have been 3 vulnerabilities in N Able with an average score of 7.8 out of ten. Last year, in 2025 N Able had 7 security vulnerabilities published. Right now, N Able is on track to have less security vulnerabilities in 2026 than it did last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.77.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 3 | 7.77 |
| 2025 | 7 | 7.00 |
| 2024 | 5 | 8.53 |
| 2023 | 1 | 7.00 |
It may take a day or so for new N Able vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent N Able Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-15580 | Aug 21, 2026 |
PassPortal v<3.49.6 Unvalidated postMessage Token Leak (Auth Abuse)vault token disclosure via unvalidated postMessage vulnerability in N-able PassPortal allows Authentication Abuse. This issue affects the PassPortal browser extension: before 3.49.6. |
|
| CVE-2026-18577 | Aug 02, 2026 |
Auth Bypass Acct Takeover in N-central 02026.3An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1 |
|
| CVE-2026-18556 | Aug 01, 2026 |
Auth Bypass via Alt Path in N-central (2026.1)Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1. |
|
| CVE-2025-11367 | Nov 12, 2025 |
RCE via Deserialization in N-central Software Probe <2025.4The N-central Software Probe < 2025.4 is vulnerable to Remote Code Execution via deserialization |
|
| CVE-2025-11366 | Nov 12, 2025 |
N-central <2025.4 Auth Bypass via Path Trvser (CVE-2025-11366)N-central < 2025.4 is vulnerable to authentication bypass via path traversal |
|
| CVE-2025-11700 | Nov 12, 2025 |
N-central <2025.4 XXE Info DisclosureN-central versions < 2025.4 are vulnerable to multiple XML External Entities injection leading to information disclosure |
|
| CVE-2025-9316 | Nov 12, 2025 |
Unauth SessionID Generation in N-central < 2025.4N-central < 2025.4 can generate sessionIDs for unauthenticated users This issue affects N-central: before 2025.4. |
|
| CVE-2025-10231 | Sep 10, 2025 |
N-Central Windows Agent/Probe Privilege Escalation via File PermissionAn Incorrect File Handling Permission bug exists on the N-central Windows Agent and Probe that, in the right circumstances, can allow a local low-level user to run commands with elevated permissions. |
|
| CVE-2025-8876 | Aug 14, 2025 |
N-able N-central OS Command Injection before 2025.3.1Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-central: before 2025.3.1. |
|
| CVE-2025-8875 | Aug 14, 2025 |
Deserialization of Untrusted Data in N-able N-central <2025.3.1 Leads to LCEDeserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-central: before 2025.3.1. |
|