N-able / N-central
16 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-86218 KEV | pre-authentication remote code execution | CRITICAL | 10.0 | Sep 6, 2026 |
| CVE-2026-86206 | Access control filter bypass allows unauthorised access to APIs | MEDIUM | 6.9 | Sep 5, 2026 |
| CVE-2026-86207 | Authentication bypass leads to unauthorised access to N-central | HIGH | 7.7 | Sep 5, 2026 |
| CVE-2026-18577 KEV | Incomplete patch leads to administrative account takeover | HIGH | 8.2 | Aug 2, 2026 |
| CVE-2026-18556 KEV | Unauthenticated administrative account takeover | HIGH | 8.2 | Aug 1, 2026 |
| CVE-2025-11367 | N-central windows software probe Remote Code Execution | CRITICAL | 10.0 | Nov 12, 2025 |
| CVE-2025-11366 | N-central Authentication bypass via path traversal | CRITICAL | 9.4 | Nov 12, 2025 |
| CVE-2025-11700 | N-central Multiple XXE Injection Vulnerabilities | HIGH | 8.4 | Nov 12, 2025 |
| CVE-2025-9316 | N-central unauthenticated sessionID generation | MEDIUM | 6.9 | Nov 12, 2025 |
| CVE-2025-10231 | N-central Incorrect Default Permissions could lead to Privilege Escalation | HIGH | 7.8 | Sep 10, 2025 |
| CVE-2025-7051 | N-central Syslog Configuration Insecure Direct Object Reference | HIGH | 8.3 | Aug 21, 2025 |
| CVE-2025-8875 KEV | Insecure Deserialization Vulnerability | CRITICAL | 9.4 | Aug 14, 2025 |
| CVE-2025-8876 KEV | Command Injection Vulnerability | CRITICAL | 9.4 | Aug 14, 2025 |
| CVE-2024-8510 | N-central Path Traversal | MEDIUM | 5.3 | Mar 17, 2025 |
| CVE-2024-28200 | N-central Authentication Bypass | CRITICAL | 9.8 | Jul 1, 2024 |
| CVE-2024-5322 | N-central Authentication Bypass via Session Rebinding | CRITICAL | 9.1 | Jul 1, 2024 |
| CVE-2023-47132 | An issue discovered in N-able N-central before 2023.6 and earlier allows attackers to gain escalated privileges via API calls. | CRITICAL | 9.8 | Feb 8, 2024 |
| CVE-2023-30297 | An issue found in N-able Technologies N-central Server before 2023.4 allows a local attacker to execute arbitrary code via the monitoring function of the serve… | HIGH | 7.0 | Aug 3, 2023 |
Showing 1 to 16 of 16 CVEs