N-able
First CVE: Jul 1, 2024Active for: 2 years
12
CVEs Published
More CVEs Published than 30% of tracked CNAs
6.0
Avg CVEs / Year
More Avg CVEs / Year than 37% of tracked CNAs
7.9
Avg CVSS Score
Higher Avg CVSS Score than 83% of tracked CNAs
16.7%
In CISA KEV
Higher KEV Rate than 99% of tracked CNAs
Self-Reporting Analysis
Of all the CVEs published by N-able as a CNA, 91.7% affect products that N-able develops as a vendor.
91.7%
Self-reported: 11Third-party: 1
Of all the CVEs published that affect products developed by N-able, 68.8% are self-published by N-able as a CNA.
68.8%
31.3%
Self-published: 11Published by other CNAs: 5
Trends Over Time
The number and severity of CVEs published by N-able over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 1, 2024
2 years ago
Most Recent CVE
Nov 12, 2025
254 days ago
Top CVEs
All CVEs published by N-able as a CNA, regardless of affected vendor or product.
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-8876HIGH Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-central: before 2025.3.1. | Aug 14, 2025 | 8.8 | 73 | YES | NO |
CVE-2025-8875HIGH Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-central: before 2025.3.1. | Aug 14, 2025 | 7.8 | 70 | YES | NO |
CVE-2025-9316MEDIUM N-central < 2025.4 can generate sessionIDs for unauthenticated users
This issue affects N-central: before 2025.4. | Nov 12, 2025 | 6.9 | 69 | NO | YES |
CVE-2025-11700HIGH N-central versions < 2025.4 are vulnerable to multiple XML External Entities injection leading to information disclosure | Nov 12, 2025 | 7.5 | 67 | NO | YES |
CVE-2024-28200CRITICAL The N-central server is vulnerable to an authentication bypass of the user interface. This vulnerability is present in all deployments of N-central prior to 2024.2.
This vulnerabi | Jul 1, 2024 | 9.8 | 39 | NO | YES |
CVE-2025-11367CRITICAL The N-central Software Probe < 2025.4 is vulnerable to Remote Code Execution via deserialization | Nov 12, 2025 | 9.8 | 33 | NO | NO |
CVE-2025-11366CRITICAL N-central < 2025.4 is vulnerable to authentication bypass via path traversal | Nov 12, 2025 | 9.8 | 32 | NO | NO |
CVE-2025-10231HIGH An Incorrect File Handling Permission bug exists on the N-central Windows Agent and Probe that, in the right circumstances, can allow a local low-level user to run commands with el | Sep 10, 2025 | 7.8 | 26 | NO | NO |
CVE-2025-7051HIGH On N-central, it is possible for any authenticated user to read, write and modify syslog configuration across customers on an N-central server. This vulnerability is present in all | Aug 21, 2025 | 8.3 | 25 | NO | NO |
CVE-2024-5322CRITICAL The N-central server is vulnerable to session rebinding of already authenticated users when using Entra SSO, which can lead to authentication bypass.
This vulnerability is presen | Jul 1, 2024 | 9.1 | 25 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA12 CVEs
8%
17%
42%
33%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (16.7%)
Network10 (83.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None12 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low4 (33.3%)
High1 (8.3%)
None7 (58.3%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (12 CVEs).
CISA KEV
2 CVEs
16.7% of CVEs· 99th percentile
Metasploit
2 CVEs
16.7% of CVEs· 100th percentile
Nuclei
3 CVEs
25.0% of CVEs· 100th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by N-able as a CNA.
Media Mentions
Media articles that mention a CVE ID published by N-able as a CNA — matched by CVE ID, not by organization name.