Database/Control plane, storage & DevOps

N-able N-central: Deserialization of untrusted data allowing local code execution on the RMM server
CVSS 7.8CVE-2025-8875Control plane, storage & DevOpsKnown exploitedcurated
Impact
Deserialization of untrusted data allowing local code execution on the RMM server
Who can reach it
Local
What to do
Control-plane: patch to 2025.3.1+; the RMM reaches every managed host
References
Related entries
- N-able N-central: Authentication bypass using an alternate path or channel on the RMM serverCVE-2026-18556 · N-able N-centralHigh
- N-able N-central: Improper input validationCVE-2025-8876 · N-able N-centralHigh
- N-able N-central: Incomplete patch for CVE-2026-18556CVE-2026-18577 · N-able N-centralHigh
- ansible-core: malicious Galaxy role injects git flags to run code on the machine installing itCVE-2026-11332 · ansible-core (ansible-galaxy role install, git argument injection via meta/requirements.yml)High
- ansible-core: git argument injection in ansible-galaxy collection install yields command executionCVE-2026-16493 · ansible-core (ansible-galaxy collection install, git source URL handling)High
- MUNGE (munged credential daemon): This is the root of trust under Slurm. A crafted message with an oversizedCVE-2026-25506 · MUNGE (munged credential daemon)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.