CVE-2025-68624 is a design-level authorization flaw in N-able Mail Assure that allows an authenticated SMTP user to send outbound email using MAIL FROM addresses belonging to other tenants. This issue enables an attacker from any tenant to impersonate other tenant domains, producing messages that pass SPF and DMARC validation. The vulnerability exists due to a lack of domain-to-account binding enforcement [truncated]
The CVE-2026-15580 vulnerability in N-able PassPortal browser extension versions before 3.49.6 allows for vault token disclosure via unvalidated postMessage, potentially leading to authentication abuse. This issue affects organizations using the PassPortal browser extension. The CVE record was published on 2026-08-21T14:16:48.587Z and has not been modified since then. The vulnerability has a CVSS score of [truncated]
CVE-2026-18556: N-able N-central Authentication Bypass Vulnerability Debrief. This high-severity vulnerability allows for authentication bypass in N-able N-central deployments. Defenders should assess exposure, prioritize patching and mitigation, and adhere to CISA’s BOD 26-04 guidance. The vulnerability's existence is confirmed by the CISA Known Exploited Vulnerabilities catalog and CVE Program record. A [truncated]
CVE-2025-8876 is a command injection vulnerability affecting N-able N-Central and has been added to CISA's Known Exploited Vulnerabilities catalog. That makes it a priority issue for defenders because CISA treats it as actively exploited. The supplied source corpus does not include a CVSS score or deeper exploit conditions, so response should be driven by the KEV listing and vendor guidance.
CVE-2025-8875 is an N-able N-Central insecure deserialization vulnerability that CISA listed in the Known Exploited Vulnerabilities catalog on 2025-08-13. For defenders, the important takeaway is operational urgency: CISA set a remediation due date of 2025-08-20, and the supplied guidance says to apply vendor mitigations, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the p [truncated]