VendorsN-ablen-centralany version
Vulnerabilities

N-able N-central any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2026-86218
pre-authentication remote code execution
Published 2026-09-06 · Analyzed
10.0KEVEPSS 0.129
CVE-2025-11367
N-central windows software probe Remote Code Execution
Published 2025-11-12 · Analyzed
10.0EPSS 0.006
CVE-2024-28200
N-central Authentication Bypass
Published 2024-07-01 · Modified
9.8EPSS 0.019
CVE-2025-11366
N-central Authentication bypass via path traversal
Published 2025-11-12 · Analyzed
9.8EPSS 0.006
CVE-2023-47132
An issue discovered in N-able N-central before 2023.6 and earlier allows attackers to gain escalated privileges via API calls.
Published 2024-02-08 · Modified
9.8EPSS 0.006
CVE-2025-8876
Command Injection Vulnerability
Published 2025-08-14 · Analyzed
9.4KEVEPSS 0.034
CVE-2025-8875
Insecure Deserialization Vulnerability
Published 2025-08-14 · Analyzed
9.4KEVEPSS 0.019
CVE-2024-5322
N-central Authentication Bypass via Session Rebinding
Published 2024-07-01 · Analyzed
9.1EPSS 0.004
CVE-2025-11700
N-central Multiple XXE Injection Vulnerabilities
Published 2025-11-12 · Modified
8.4EPSS 0.307
CVE-2025-7051
N-central Syslog Configuration Insecure Direct Object Reference
Published 2025-08-21 · Analyzed
8.3EPSS 0.003
CVE-2026-18577
Incomplete patch leads to administrative account takeover
Published 2026-08-02 · Analyzed
8.2KEVEPSS 0.146
CVE-2026-18556
Unauthenticated administrative account takeover
Published 2026-08-01 · Analyzed
8.2KEVEPSS 0.079
CVE-2025-10231
N-central Incorrect Default Permissions could lead to Privilege Escalation
Published 2025-09-10 · Analyzed
7.8EPSS 0.001
CVE-2023-30297
An issue found in N-able Technologies N-central Server before 2023.4 allows a local attacker to execute arbitrary code via the monitoring function of the server.
Published 2023-08-03 · Modified
7.0EPSS 0.002
CVE-2024-8510
N-central Path Traversal
Published 2025-03-17 · Analyzed
5.3EPSS 0.004