N-able records
18 published records for vendor n-able.
Researcher profile
- Entered KEV
- 5 · 27.8%
- Weaponized
- 6 · 33.3%
- Pre-auth RCE
- 2
- With a fix record
- 22.2%
- Median publish → KEV
- 1 days
Recurring classes
- CWE-288 Authentication Bypass Using an Alternate Path or Channel4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-502 Deserialization of Untrusted Data2
- CWE-284 Improper Access Control1
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
- CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition1
The weakness classes this vendor ships most often: where to look.
CWEAll records
18 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
74This week | CVE-2026-86218Weaponized | pre-authentication remote code executionn-able · n-central · CWE-96 | Critical10.0 | KEV | 12.9% | Sep 5, 2026 |
68This week | CVE-2025-8876Weaponized | Command Injection Vulnerabilityn-able · n-central · CWE-20 | Critical9.4 | KEV | 3.4% | Aug 14, 2025 |
68This week | CVE-2025-8875Weaponized | Insecure Deserialization Vulnerabilityn-able · n-central · CWE-502 | Critical9.4 | KEV | 1.9% | Aug 14, 2025 |
66This week | CVE-2026-18577Weaponized | Incomplete patch leads to administrative account takeovern-able · n-central · CWE-288 | High8.2 | KEV | 14.6% | Aug 2, 2026 |
64This week | CVE-2026-18556Weaponized | Unauthenticated administrative account takeovern-able · n-central · CWE-288 | High8.2 | KEV | 7.9% | Aug 1, 2026 |
42Plan | CVE-2025-11700Weaponized | N-central Multiple XXE Injection Vulnerabilitiesn-able · n-central · CWE-611 | High8.4 | — | 30.7% | Nov 12, 2025 |
40Plan | CVE-2024-28200Proof of concept | N-central Authentication Bypassn-able · n-central · CWE-288 | Critical9.8 | — | 1.9% | Jul 1, 2024 |
40Plan | CVE-2025-11367No exploit | N-central windows software probe Remote Code Executionn-able · n-central · CWE-502 | Critical10.0 | — | 0.6% | Nov 12, 2025 |
39Monitor | CVE-2023-47132No exploit | An issue discovered in N-able N-central before 2023.6 and earlier allows attackers to gain escalated privileges via API calls.n-able · n-central · CWE-269 | Critical9.8 | — | 0.6% | Feb 8, 2024 |
37Monitor | CVE-2025-11366No exploit | N-central Authentication bypass via path traversaln-able · n-central · CWE-22 | Critical9.4 | — | 0.6% | Nov 12, 2025 |
36Monitor | CVE-2024-5322No exploit | N-central Authentication Bypass via Session Rebindingn-able · n-central · CWE-288 | Critical9.1 | — | 0.4% | Jul 1, 2024 |
33Monitor | CVE-2025-7051No exploit | N-central Syslog Configuration Insecure Direct Object Referencen-able · n-central · CWE-284 | High8.3 | — | 0.3% | Aug 21, 2025 |
31Monitor | CVE-2025-10231No exploit | N-central Incorrect Default Permissions could lead to Privilege Escalationn-able · n-central · CWE-276 | High7.8 | — | 0.1% | Sep 10, 2025 |
30Monitor | CVE-2023-47131No exploit | The N-able PassPortal extension before 3.29.2 for Chrome inserts sensitive information into a log file.n-able · passportal · CWE-532 | High7.5 | — | 0.5% | Feb 8, 2024 |
28Monitor | CVE-2023-27470Proof of concept | BASupSrvcUpdater.exe in N-able Take Control Agent through 7.0.41.1141 before 7.0.43 has a TOCTOU Race Condition via a pseudo-symlink at %PROn-able · take control · CWE-367 | High7.0 | — | 0.5% | Sep 11, 2023 |
28Monitor | CVE-2023-37244No exploit | Privilege escalation in N-Able's AutomationManagerAgentn-able · automation manager · CWE-362 | High7.0 | — | 0.2% | May 2, 2024 |
28Monitor | CVE-2023-30297No exploit | An issue found in N-able Technologies N-central Server before 2023.4 allows a local attacker to execute arbitrary code via the monitoring fun-able · n-central | High7.0 | — | 0.2% | Aug 3, 2023 |
21Monitor | CVE-2024-8510No exploit | N-central Path Traversaln-able · n-central · CWE-22 | Medium5.3 | — | 0.4% | Mar 17, 2025 |
- CVE-2026-8621874This week
pre-authentication remote code execution
CriticalCVSS 10.0KEVWeaponizedEPSS 13%n-able · n-centralSep 5, 2026
- CVE-2025-887668This week
Command Injection Vulnerability
CriticalCVSS 9.4KEVWeaponizedEPSS 3%n-able · n-centralAug 14, 2025
- CVE-2025-887568This week
Insecure Deserialization Vulnerability
CriticalCVSS 9.4KEVWeaponizedEPSS 2%n-able · n-centralAug 14, 2025
- CVE-2026-1857766This week
Incomplete patch leads to administrative account takeover
HighCVSS 8.2KEVWeaponizedEPSS 15%n-able · n-centralAug 2, 2026
- CVE-2026-1855664This week
Unauthenticated administrative account takeover
HighCVSS 8.2KEVWeaponizedEPSS 8%n-able · n-centralAug 1, 2026
- CVE-2025-1170042Plan
N-central Multiple XXE Injection Vulnerabilities
HighCVSS 8.4WeaponizedEPSS 31%n-able · n-centralNov 12, 2025
- CVE-2024-2820040Plan
N-central Authentication Bypass
CriticalCVSS 9.8Proof of conceptEPSS 2%n-able · n-centralJul 1, 2024
- CVE-2025-1136740Plan
N-central windows software probe Remote Code Execution
CriticalCVSS 10.0No exploitEPSS 1%n-able · n-centralNov 12, 2025
- CVE-2023-4713239Monitor
An issue discovered in N-able N-central before 2023.6 and earlier allows attackers to gain escalated privileges via API calls.
CriticalCVSS 9.8No exploitEPSS 1%n-able · n-centralFeb 8, 2024
- CVE-2025-1136637Monitor
N-central Authentication bypass via path traversal
CriticalCVSS 9.4No exploitEPSS 1%n-able · n-centralNov 12, 2025
- CVE-2024-532236Monitor
N-central Authentication Bypass via Session Rebinding
CriticalCVSS 9.1No exploitEPSS 0%n-able · n-centralJul 1, 2024
- CVE-2025-705133Monitor
N-central Syslog Configuration Insecure Direct Object Reference
HighCVSS 8.3No exploitEPSS 0%n-able · n-centralAug 21, 2025
- CVE-2025-1023131Monitor
N-central Incorrect Default Permissions could lead to Privilege Escalation
HighCVSS 7.8No exploitEPSS 0%n-able · n-centralSep 10, 2025
- CVE-2023-4713130Monitor
The N-able PassPortal extension before 3.29.2 for Chrome inserts sensitive information into a log file.
HighCVSS 7.5No exploitEPSS 0%n-able · passportalFeb 8, 2024
- CVE-2023-2747028Monitor
BASupSrvcUpdater.exe in N-able Take Control Agent through 7.0.41.1141 before 7.0.43 has a TOCTOU Race Condition via a pseudo-symlink at %PRO
HighCVSS 7.0Proof of conceptEPSS 1%n-able · take controlSep 11, 2023
- CVE-2023-3724428Monitor
Privilege escalation in N-Able's AutomationManagerAgent
HighCVSS 7.0No exploitEPSS 0%n-able · automation managerMay 2, 2024
- CVE-2023-3029728Monitor
An issue found in N-able Technologies N-central Server before 2023.4 allows a local attacker to execute arbitrary code via the monitoring fu
HighCVSS 7.0No exploitEPSS 0%n-able · n-centralAug 3, 2023
- CVE-2024-851021Monitor
N-central Path Traversal
MediumCVSS 5.3No exploitEPSS 0%n-able · n-centralMar 17, 2025