CVE-2025-8875

Insecure Deserialization Vulnerability

Basic Information

CVE State
PUBLISHED
Reserved Date
August 11, 2025
Published Date
August 14, 2025
Last Updated
October 21, 2025
Vendor
N-able
Product
N-central
Description
Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-central: before 2025.3.1.
Tags
cisa

CVSS Scores

CVSS v4.0

9.4 - CRITICAL

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

SSVC Information

Exploitation
active
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (2026-06-01 10:38:55 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CVE 2026-06-01 10:38:55 UTC

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel