This story started last week, but was updated Tuesday.
Attackers are exploiting two vulnerabilities in the N-central remote monitoring and management solution by N-able. The vulnerabilities, identified as CVE-2025-8875, an insecure deserialization flaw, and CVE-2025-8876, a command injection vulnerability, have been confirmed by the United States Cybersecurity and Infrastructure Security Agency. While there are no public reports of exploitation, the agency has added these flaws to its Known Exploited Vulnerabilities catalog and mandated that federal agencies mitigate them within a week. N-able N-central is widely used by managed service providers and IT teams to monitor and secure a variety of devices. The company has acknowledged that the vulnerabilities require attackers to authenticate themselves before exploitation, suggesting that there is a risk to the security of customers’ N-central environments if left unpatched. N-able has released updates to fix these vulnerabilities and is urging customers to upgrade to the latest versions of N-central to safeguard their systems. A spokesperson for N-able indicated that there is evidence of limited exploitation in on-premises environments but no confirmed incidents in hosted cloud environments.
And the update — Over 800 N-able N-central servers remain unpatched against critical security vulnerabilities that have been actively exploited. These vulnerabilities allow authenticated attackers to execute commands on unpatched devices due to improper sanitization of user input and an insecure deserialization weakness. According to the Shadowserver Foundation, 880 N-central servers, primarily located in the United States, Canada, and the Netherlands, are still vulnerable. The U.S. Cybersecurity and Infrastructure Security Agency has classified these flaws as exploited in zero-day attacks and mandated that all federal agencies patch their systems by August 20, 2025. N-able has urged administrators to upgrade to the latest version of their software to mitigate these risks.
Why do we care?
Disclosure, I’m an N-Able Shareholder. Here we go again—an RMM tool is the attack vector. N-able’s N-central has two nasty flaws, and guess what? They’re being exploited. Shadowserver says nearly 900 servers are still unpatched. That’s 900 MSPs leaving the door wide open.
Yeah, N-able says you need to be authenticated to pull this off. Big deal—if the bad guys already have a foothold, that’s plenty. And remember, your RMM isn’t just another app. It’s the master key to every client system.
N-able’s response checks the “we patched, we communicated” boxes, but it doesn’t feel like the company is treating this with the existential gravity it deserves. By emphasizing “authentication required” and “limited exploitation,” N-able risks minimizing the urgency rather than driving home the message that this patch is non-negotiable.
For MSPs, the safe assumption is that your RMM will be targeted, and you can’t rely on vendor spin to gauge severity. Apply updates immediately, validate logs for suspicious activity, and push your vendor for long-term proof they’re hardening the product—not just fixing the bug of the week.

