{"id":133882,"date":"2025-11-20T11:24:01","date_gmt":"2025-11-20T11:24:01","guid":{"rendered":"https:\/\/cybersecuritynews.com\/?p=133882"},"modified":"2025-11-20T11:24:08","modified_gmt":"2025-11-20T11:24:08","slug":"critical-n-able-n-central-vulnerabilities","status":"publish","type":"post","link":"https:\/\/cybersecuritynews.com\/critical-n-able-n-central-vulnerabilities\/","title":{"rendered":"Critical N-able N-central Vulnerabilities Allow attacker to interact with legacy APIs and read sensitive files"},"content":{"rendered":"\n<p>N-able&#8217;s N-central remote management and monitoring (RMM) platform faces critical security risks following the discovery of multiple vulnerabilities.<\/p>\n\n\n\n<p>According to Horizon3.ai, it allows unauthenticated attackers to <a href=\"https:\/\/cybersecuritynews.com\/hashicorp-vault-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">bypass authentication<\/a>, access legacy APIs, and exfiltrate sensitive files, including credentials and database backups.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-the-vulnerability-chain\"><strong>The Vulnerability Chain<\/strong><\/h2>\n\n\n\n<p>Earlier this year, N-able N-central was added to the CISA Known Exploited Vulnerabilities (KEV) catalog for<a href=\"https:\/\/cybersecuritynews.com\/1000-exposed-n-able-n-central-rmm-servers\/\" target=\"_blank\" rel=\"noreferrer noopener\"> CVE-2025-8875<\/a> and <a href=\"https:\/\/cybersecuritynews.com\/1000-exposed-n-able-n-central-rmm-servers\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2025-8876<\/a>.<\/p>\n\n\n\n<p>These vulnerabilities enable authenticated attackers to achieve remote code execution via deserialization and command injection.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEigNG-WHUo9Mm1zP7XLpBv0UMxzglFgl3FwTcNlRcer25JmXSD_EK9jwjRTzHrIQBiH_Pbb3bWTnxeeO_OvHegPysEzAo6rD_euE8RMREboAGK5VTJxAVVlSBRnr5O9CEeu3PMkj4C5zMyMFtFV_h3LPn1dV-p4C8GzzLQb7SQHBI0tYkonwh7S9mrRrPo\/s1600\/Screenshot%202025-11-20%20155924%20%281%29.webp\" alt=\"\"\/><figcaption class=\"wp-element-caption\"><em>Shodan Exposure<\/em><\/figcaption><\/figure>\n\n\n\n<p>Horizon3.ai researchers found more serious flaws in the latest versions. They also uncovered new weaknesses and built a dangerous attack chain.<\/p>\n\n\n\n<figure class=\"wp-block-table is-style-stripes\"><table class=\"has-fixed-layout\"><thead><tr><td><strong>Aspect<\/strong><\/td><td><strong>CVE-2025-9316<\/strong><\/td><td><strong>CVE-2025-11700<\/strong><\/td><\/tr><\/thead><tbody><tr><td>CVE ID<\/td><td>CVE-2025-9316<\/td><td>CVE-2025-11700<\/td><\/tr><tr><td>Vulnerability Name<\/td><td>Authentication Bypass via Weak Authentication Method<\/td><td>XML External Entity (XXE) Information Leak<\/td><\/tr><tr><td>CVSS Score<\/td><td>9.1<\/td><td>8.2<\/td><\/tr><tr><td>Severity<\/td><td>Critical<\/td><td>High<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>An <a href=\"https:\/\/cybersecuritynews.com\/f5-critical-bug\/\" target=\"_blank\" rel=\"noreferrer noopener\">unauthenticated <\/a>attacker<a href=\"https:\/\/cybersecuritynews.com\/f5-critical-bug\/\" target=\"_blank\" rel=\"noreferrer noopener\"> <\/a>can exploit&nbsp;CVE-2025-9316, a weak authentication bypass in the legacy SOAP API, to obtain valid session IDs.<\/p>\n\n\n\n<p>This initial access opens doors to&nbsp;CVE-2025-11700, an XML External Entity (<a href=\"https:\/\/cybersecuritynews.com\/poc-exploit-xxe-injection-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">XXE<\/a>) injection vulnerability that allows reading arbitrary files from the filesystem.<\/p>\n\n\n\n<p>With approximately 3,000 N-central instances exposed on the internet according to Shodan, the attack surface is significant.<\/p>\n\n\n\n<p>Horizon3.ai researchers <a href=\"https:\/\/horizon3.ai\/attack-research\/attack-blogs\/n-able-n-central-from-n-days-to-0-days\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">demonstrated<\/a> how attackers can chain these vulnerabilities to read sensitive configuration files, including\u00a0\/opt\/nable\/var\/ncsai\/etc\/ncbackup.conf, which contains database backup credentials stored in cleartext.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhZ_3JDws2RDih0ZYHjj0rwHGCfshp9bkrCIwIZHU_DekEd7kZhO3zqItYC07TEYW3__pNatgMvxxP8BtR5GdIvlxP7OnA0giGHCe4_5bsMZlZW8AEOgLPdqdImWv7_03D3sskrhIEzlr08dhWw9PdcD2O8OQbo89WJeURB5Hs2ef0JD-n1swhHdGUOavM\/s1600\/Screenshot%202025-11-20%20160208%20%281%29.webp\" alt=\"Decrypting secrets given masterPassword and keystore.bcfks\"\/><figcaption class=\"wp-element-caption\"><em>Decrypting secrets given masterPassword and keystore.bcfks<\/em><\/figcaption><\/figure><\/div>\n\n\n<p>Most critically, accessing the N-central database backup reveals all integration secrets: domain credentials, API keys, SSH private keys, and encrypted database entries.<\/p>\n\n\n\n<p>Using cryptographic keys stored in the backup (masterPassword&nbsp;and&nbsp;keystore.bcfks), attackers can decrypt all stored secrets, leading to complete infrastructure compromise.<\/p>\n\n\n\n<p>N-able addressed these vulnerabilities in version\u00a02025.4.0.9,\u00a0released on November 5, 2025, by restricting access to vulnerable legacy <a href=\"https:\/\/cybersecuritynews.com\/best-api-security-testing-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">SOAP API endpoints<\/a>.<\/p>\n\n\n\n<p>Organizations should upgrade immediately and review logs for indicators of exploitation, including &#8220;Failed to import service template&#8221; entries in&nbsp;dmsservice.log.<\/p>\n\n\n\n<p>The vulnerability chain demonstrates why legacy API endpoints pose persistent security risks in enterprise software, particularly for widely deployed RMM solutions that threat actors commonly target.<\/p>\n\n\n\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>N-able&#8217;s N-central remote management and monitoring (RMM) platform faces critical security risks following the discovery of multiple vulnerabilities. According to Horizon3.ai, it allows unauthenticated attackers to bypass authentication, access legacy APIs, and exfiltrate sensitive files, including credentials and database backups. The Vulnerability Chain Earlier this year, N-able N-central was added to the CISA Known Exploited [&hellip;]<\/p>\n","protected":false},"author":27,"featured_media":133904,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhqsS6DFFfo85-SGKph51kaj9MEcVqrnKpKG8kp1VfiIENgyXc9HH8P7pvWwXhRUr-IUlJXXABDYjKdbkpN3nG46dplW0FJw5Fveh8_KpotIxPfkPpgIGkFPc1-cvdq8sbkYQccDzf9aCrWHVlSDBRPKx_o5Q7pshp0hDHc3bfmHSs5rC7zQO33-6BCJbM\/s1600\/Critical%20N-able%20N-central%20Vulnerabilities%20Allow%20attacker%20to%20interact%20with%20legacy%20APIs%20and%20read%20sensitive%20files%20%281%29%20%281%29.webp","fifu_image_alt":"N-able N-central Vulnerabilities","_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[11,2737],"tags":[2283,149,151],"class_list":{"0":"post-133882","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-cyber-security-news","8":"category-vulnerability-news","9":"tag-cve-vulnerabilities","10":"tag-cyber-security","11":"tag-cyber-security-news"},"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v25.7.1 (Yoast SEO v25.7) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Critical N-able N-central Vulnerabilities Allow attacker to interact with legacy APIs and read sensitive files<\/title>\n<meta name=\"description\" content=\"N-able&#039;s N-central platform has flaws, allows attackers to bypass authentication, access legacy APIs, and exfiltrate sensitive files.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/cybersecuritynews.com\/critical-n-able-n-central-vulnerabilities\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Critical N-able N-central Vulnerabilities Allow attacker to interact with legacy APIs and read sensitive files\" \/>\n<meta property=\"og:description\" content=\"N-able&#039;s N-central platform has flaws, allows attackers to bypass authentication, access legacy APIs, and exfiltrate sensitive files.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/cybersecuritynews.com\/critical-n-able-n-central-vulnerabilities\/\" \/>\n<meta property=\"og:site_name\" content=\"Cyber Security News\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hackingtutorialsandnews\" \/>\n<meta property=\"article:published_time\" content=\"2025-11-20T11:24:01+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-11-20T11:24:08+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhqsS6DFFfo85-SGKph51kaj9MEcVqrnKpKG8kp1VfiIENgyXc9HH8P7pvWwXhRUr-IUlJXXABDYjKdbkpN3nG46dplW0FJw5Fveh8_KpotIxPfkPpgIGkFPc1-cvdq8sbkYQccDzf9aCrWHVlSDBRPKx_o5Q7pshp0hDHc3bfmHSs5rC7zQO33-6BCJbM\/s1600\/Critical%20N-able%20N-central%20Vulnerabilities%20Allow%20attacker%20to%20interact%20with%20legacy%20APIs%20and%20read%20sensitive%20files%20%281%29%20%281%29.webp\" \/><meta property=\"og:image\" content=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhqsS6DFFfo85-SGKph51kaj9MEcVqrnKpKG8kp1VfiIENgyXc9HH8P7pvWwXhRUr-IUlJXXABDYjKdbkpN3nG46dplW0FJw5Fveh8_KpotIxPfkPpgIGkFPc1-cvdq8sbkYQccDzf9aCrWHVlSDBRPKx_o5Q7pshp0hDHc3bfmHSs5rC7zQO33-6BCJbM\/s1600\/Critical%20N-able%20N-central%20Vulnerabilities%20Allow%20attacker%20to%20interact%20with%20legacy%20APIs%20and%20read%20sensitive%20files%20%281%29%20%281%29.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"662\" \/>\n\t<meta property=\"og:image:height\" content=\"377\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Abinaya\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhqsS6DFFfo85-SGKph51kaj9MEcVqrnKpKG8kp1VfiIENgyXc9HH8P7pvWwXhRUr-IUlJXXABDYjKdbkpN3nG46dplW0FJw5Fveh8_KpotIxPfkPpgIGkFPc1-cvdq8sbkYQccDzf9aCrWHVlSDBRPKx_o5Q7pshp0hDHc3bfmHSs5rC7zQO33-6BCJbM\/s1600\/Critical%20N-able%20N-central%20Vulnerabilities%20Allow%20attacker%20to%20interact%20with%20legacy%20APIs%20and%20read%20sensitive%20files%20%281%29%20%281%29.webp\" \/>\n<meta name=\"twitter:creator\" content=\"@The_Cyber_News\" \/>\n<meta name=\"twitter:site\" content=\"@The_Cyber_News\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Abinaya\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Critical N-able N-central Vulnerabilities Allow attacker to interact with legacy APIs and read sensitive files","description":"N-able's N-central platform has flaws, allows attackers to bypass authentication, access legacy APIs, and exfiltrate sensitive files.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/cybersecuritynews.com\/critical-n-able-n-central-vulnerabilities\/","og_locale":"en_US","og_type":"article","og_title":"Critical N-able N-central Vulnerabilities Allow attacker to interact with legacy APIs and read sensitive files","og_description":"N-able's N-central platform has flaws, allows attackers to bypass authentication, access legacy APIs, and exfiltrate sensitive files.","og_url":"https:\/\/cybersecuritynews.com\/critical-n-able-n-central-vulnerabilities\/","og_site_name":"Cyber Security News","article_publisher":"https:\/\/www.facebook.com\/Hackingtutorialsandnews","article_published_time":"2025-11-20T11:24:01+00:00","article_modified_time":"2025-11-20T11:24:08+00:00","og_image":[{"url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhqsS6DFFfo85-SGKph51kaj9MEcVqrnKpKG8kp1VfiIENgyXc9HH8P7pvWwXhRUr-IUlJXXABDYjKdbkpN3nG46dplW0FJw5Fveh8_KpotIxPfkPpgIGkFPc1-cvdq8sbkYQccDzf9aCrWHVlSDBRPKx_o5Q7pshp0hDHc3bfmHSs5rC7zQO33-6BCJbM\/s1600\/Critical%20N-able%20N-central%20Vulnerabilities%20Allow%20attacker%20to%20interact%20with%20legacy%20APIs%20and%20read%20sensitive%20files%20%281%29%20%281%29.webp","type":"","width":"","height":""},{"width":662,"height":377,"url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhqsS6DFFfo85-SGKph51kaj9MEcVqrnKpKG8kp1VfiIENgyXc9HH8P7pvWwXhRUr-IUlJXXABDYjKdbkpN3nG46dplW0FJw5Fveh8_KpotIxPfkPpgIGkFPc1-cvdq8sbkYQccDzf9aCrWHVlSDBRPKx_o5Q7pshp0hDHc3bfmHSs5rC7zQO33-6BCJbM\/s1600\/Critical%20N-able%20N-central%20Vulnerabilities%20Allow%20attacker%20to%20interact%20with%20legacy%20APIs%20and%20read%20sensitive%20files%20%281%29%20%281%29.webp","type":"image\/jpeg"}],"author":"Abinaya","twitter_card":"summary_large_image","twitter_image":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhqsS6DFFfo85-SGKph51kaj9MEcVqrnKpKG8kp1VfiIENgyXc9HH8P7pvWwXhRUr-IUlJXXABDYjKdbkpN3nG46dplW0FJw5Fveh8_KpotIxPfkPpgIGkFPc1-cvdq8sbkYQccDzf9aCrWHVlSDBRPKx_o5Q7pshp0hDHc3bfmHSs5rC7zQO33-6BCJbM\/s1600\/Critical%20N-able%20N-central%20Vulnerabilities%20Allow%20attacker%20to%20interact%20with%20legacy%20APIs%20and%20read%20sensitive%20files%20%281%29%20%281%29.webp","twitter_creator":"@The_Cyber_News","twitter_site":"@The_Cyber_News","twitter_misc":{"Written by":"Abinaya","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"NewsArticle","@id":"https:\/\/cybersecuritynews.com\/critical-n-able-n-central-vulnerabilities\/#article","isPartOf":{"@id":"https:\/\/cybersecuritynews.com\/critical-n-able-n-central-vulnerabilities\/"},"author":{"name":"Abinaya","@id":"https:\/\/cybersecuritynews.com\/#\/schema\/person\/1a94534cae789bad6ff3d6a1c4bfcda1"},"headline":"Critical N-able N-central Vulnerabilities Allow attacker to interact with legacy APIs and read sensitive files","datePublished":"2025-11-20T11:24:01+00:00","dateModified":"2025-11-20T11:24:08+00:00","mainEntityOfPage":{"@id":"https:\/\/cybersecuritynews.com\/critical-n-able-n-central-vulnerabilities\/"},"wordCount":380,"publisher":{"@id":"https:\/\/cybersecuritynews.com\/#organization"},"image":{"@id":"https:\/\/cybersecuritynews.com\/critical-n-able-n-central-vulnerabilities\/#primaryimage"},"thumbnailUrl":"https:\/\/i2.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhqsS6DFFfo85-SGKph51kaj9MEcVqrnKpKG8kp1VfiIENgyXc9HH8P7pvWwXhRUr-IUlJXXABDYjKdbkpN3nG46dplW0FJw5Fveh8_KpotIxPfkPpgIGkFPc1-cvdq8sbkYQccDzf9aCrWHVlSDBRPKx_o5Q7pshp0hDHc3bfmHSs5rC7zQO33-6BCJbM\/s1600\/Critical%20N-able%20N-central%20Vulnerabilities%20Allow%20attacker%20to%20interact%20with%20legacy%20APIs%20and%20read%20sensitive%20files%20%281%29%20%281%29.webp?w=662&resize=662,377&ssl=1","keywords":["CVE Vulnerabilities","cyber security","cyber security news"],"articleSection":["Cyber Security News","Vulnerability News"],"inLanguage":"en-US","copyrightYear":"2025","copyrightHolder":{"@id":"https:\/\/cybersecuritynews.com\/#organization"}},{"@type":"WebPage","@id":"https:\/\/cybersecuritynews.com\/critical-n-able-n-central-vulnerabilities\/","url":"https:\/\/cybersecuritynews.com\/critical-n-able-n-central-vulnerabilities\/","name":"Critical N-able N-central Vulnerabilities Allow attacker to interact with legacy APIs and read sensitive files","isPartOf":{"@id":"https:\/\/cybersecuritynews.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/cybersecuritynews.com\/critical-n-able-n-central-vulnerabilities\/#primaryimage"},"image":{"@id":"https:\/\/cybersecuritynews.com\/critical-n-able-n-central-vulnerabilities\/#primaryimage"},"thumbnailUrl":"https:\/\/i2.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhqsS6DFFfo85-SGKph51kaj9MEcVqrnKpKG8kp1VfiIENgyXc9HH8P7pvWwXhRUr-IUlJXXABDYjKdbkpN3nG46dplW0FJw5Fveh8_KpotIxPfkPpgIGkFPc1-cvdq8sbkYQccDzf9aCrWHVlSDBRPKx_o5Q7pshp0hDHc3bfmHSs5rC7zQO33-6BCJbM\/s1600\/Critical%20N-able%20N-central%20Vulnerabilities%20Allow%20attacker%20to%20interact%20with%20legacy%20APIs%20and%20read%20sensitive%20files%20%281%29%20%281%29.webp?w=662&resize=662,377&ssl=1","datePublished":"2025-11-20T11:24:01+00:00","dateModified":"2025-11-20T11:24:08+00:00","description":"N-able's N-central platform has flaws, allows attackers to bypass authentication, access legacy APIs, and exfiltrate sensitive files.","breadcrumb":{"@id":"https:\/\/cybersecuritynews.com\/critical-n-able-n-central-vulnerabilities\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/cybersecuritynews.com\/critical-n-able-n-central-vulnerabilities\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cybersecuritynews.com\/critical-n-able-n-central-vulnerabilities\/#primaryimage","url":"https:\/\/i2.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhqsS6DFFfo85-SGKph51kaj9MEcVqrnKpKG8kp1VfiIENgyXc9HH8P7pvWwXhRUr-IUlJXXABDYjKdbkpN3nG46dplW0FJw5Fveh8_KpotIxPfkPpgIGkFPc1-cvdq8sbkYQccDzf9aCrWHVlSDBRPKx_o5Q7pshp0hDHc3bfmHSs5rC7zQO33-6BCJbM\/s1600\/Critical%20N-able%20N-central%20Vulnerabilities%20Allow%20attacker%20to%20interact%20with%20legacy%20APIs%20and%20read%20sensitive%20files%20%281%29%20%281%29.webp?w=662&resize=662,377&ssl=1","contentUrl":"https:\/\/i2.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhqsS6DFFfo85-SGKph51kaj9MEcVqrnKpKG8kp1VfiIENgyXc9HH8P7pvWwXhRUr-IUlJXXABDYjKdbkpN3nG46dplW0FJw5Fveh8_KpotIxPfkPpgIGkFPc1-cvdq8sbkYQccDzf9aCrWHVlSDBRPKx_o5Q7pshp0hDHc3bfmHSs5rC7zQO33-6BCJbM\/s1600\/Critical%20N-able%20N-central%20Vulnerabilities%20Allow%20attacker%20to%20interact%20with%20legacy%20APIs%20and%20read%20sensitive%20files%20%281%29%20%281%29.webp?w=662&resize=662,377&ssl=1","width":"662","height":"377","caption":"N-able N-central Vulnerabilities"},{"@type":"BreadcrumbList","@id":"https:\/\/cybersecuritynews.com\/critical-n-able-n-central-vulnerabilities\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/cybersecuritynews.com\/"},{"@type":"ListItem","position":2,"name":"Critical N-able N-central Vulnerabilities Allow attacker to interact with legacy APIs and read sensitive files"}]},{"@type":"WebSite","@id":"https:\/\/cybersecuritynews.com\/#website","url":"https:\/\/cybersecuritynews.com\/","name":"Cyber Security News","description":"World&#039;s #1 Premier Cybersecurity and Hacking News Portal","publisher":{"@id":"https:\/\/cybersecuritynews.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/cybersecuritynews.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/cybersecuritynews.com\/#organization","name":"Cyber Security News","url":"https:\/\/cybersecuritynews.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cybersecuritynews.com\/#\/schema\/logo\/image\/","url":"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2021\/06\/Cyber-security.jpg","contentUrl":"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2021\/06\/Cyber-security.jpg","width":200,"height":200,"caption":"Cyber Security News"},"image":{"@id":"https:\/\/cybersecuritynews.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hackingtutorialsandnews","https:\/\/x.com\/The_Cyber_News","https:\/\/www.linkedin.com\/company\/cybersecurity-news\/"]},{"@type":"Person","@id":"https:\/\/cybersecuritynews.com\/#\/schema\/person\/1a94534cae789bad6ff3d6a1c4bfcda1","name":"Abinaya","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cybersecuritynews.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/915429ce96054c30e324319044dd9dea3921978fcef4cc62ef69d7c2f53ce2a7?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/915429ce96054c30e324319044dd9dea3921978fcef4cc62ef69d7c2f53ce2a7?s=96&d=mm&r=g","caption":"Abinaya"},"description":"Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.","sameAs":["https:\/\/www.cybersecuritynews.com"],"url":"https:\/\/cybersecuritynews.com\/author\/abi\/"}]}},"jetpack_featured_media_url":"https:\/\/i2.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhqsS6DFFfo85-SGKph51kaj9MEcVqrnKpKG8kp1VfiIENgyXc9HH8P7pvWwXhRUr-IUlJXXABDYjKdbkpN3nG46dplW0FJw5Fveh8_KpotIxPfkPpgIGkFPc1-cvdq8sbkYQccDzf9aCrWHVlSDBRPKx_o5Q7pshp0hDHc3bfmHSs5rC7zQO33-6BCJbM\/s1600\/Critical%20N-able%20N-central%20Vulnerabilities%20Allow%20attacker%20to%20interact%20with%20legacy%20APIs%20and%20read%20sensitive%20files%20%281%29%20%281%29.webp?w=662&resize=662,377&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/posts\/133882","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/users\/27"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/comments?post=133882"}],"version-history":[{"count":2,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/posts\/133882\/revisions"}],"predecessor-version":[{"id":133915,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/posts\/133882\/revisions\/133915"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/media\/133904"}],"wp:attachment":[{"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/media?parent=133882"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/categories?post=133882"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/tags?post=133882"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}