N Able develops a focused portfolio of remote-management and IT-operations platforms, including N-Central, Automation Manager, PassPortal, and Take Control, that serve managed service providers and enterprises managing distributed infrastructure. The vendor's vulnerability footprint, though modest in volume, reflects the administrative and authentication demands inherent to remote-access and systems-management software. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by N Able over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-8876HIGH Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-central: before 2025.3.1. | Aug 14, 2025 | 8.8 | 73 | YES | NO |
CVE-2025-8875HIGH Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-central: before 2025.3.1. | Aug 14, 2025 | 7.8 | 70 | YES | NO |
CVE-2025-9316MEDIUM N-central < 2025.4 can generate sessionIDs for unauthenticated users
This issue affects N-central: before 2025.4. | Nov 12, 2025 | 6.9 | 69 | NO | YES |
CVE-2025-11700HIGH N-central versions < 2025.4 are vulnerable to multiple XML External Entities injection leading to information disclosure | Nov 12, 2025 | 7.5 | 67 | NO | YES |
CVE-2024-28200CRITICAL The N-central server is vulnerable to an authentication bypass of the user interface. This vulnerability is present in all deployments of N-central prior to 2024.2.
This vulnerabi | Jul 1, 2024 | 9.8 | 39 | NO | YES |
CVE-2025-11367CRITICAL The N-central Software Probe < 2025.4 is vulnerable to Remote Code Execution via deserialization | Nov 12, 2025 | 9.8 | 33 | NO | NO |
CVE-2025-11366CRITICAL N-central < 2025.4 is vulnerable to authentication bypass via path traversal | Nov 12, 2025 | 9.8 | 32 | NO | NO |
CVE-2023-47132CRITICAL An issue discovered in N-able N-central before 2023.6 and earlier allows attackers to gain escalated privileges via API calls. | Feb 8, 2024 | 9.8 | 28 | NO | NO |
CVE-2025-10231HIGH An Incorrect File Handling Permission bug exists on the N-central Windows Agent and Probe that, in the right circumstances, can allow a local low-level user to run commands with el | Sep 10, 2025 | 7.8 | 26 | NO | NO |
CVE-2025-7051HIGH On N-central, it is possible for any authenticated user to read, write and modify syslog configuration across customers on an N-central server. This vulnerability is present in all | Aug 21, 2025 | 8.3 | 25 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by N Able.
Media articles that mention a CVE ID that affects a product developed by N Able — matched by CVE ID, not by vendor name.