amibeingpwned.com N-able Passportal Vulnerability Exposes User Credentials
Article Content
- •N-able's Passportal vulnerability allows unauthorized access to user credentials.
- •Approximately 73,000 users are affected, with a CVSS score of 9.4.
- •N-able issued a patch within 24 hours of the vulnerability being reported.
A vulnerability in N-able's Passportal password manager allows any malicious website to gain complete access to user credentials for up to 100 days. The issue, identified by Bay Area Labs, stems from the browser extension's failure to validate the origin of messages, enabling attackers to exploit access tokens. The vulnerability affects approximately 73,000 weekly active users and has been assigned CVE-2026-15580. N-able patched the issue within 24 hours of being notified, but the design flaws raise ongoing security concerns. Users are advised to remain vigilant as the cloud-based architecture may still pose risks. The vulnerability was discovered on July 8, 2026.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-15580 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…
Critical Zero-Day Exploits in Citrix NetScaler Confirmed by CISA On September 26, 2026, CISA confirmed the active exploitation of two critical zero-day vulnerabilities in Citrix NetScaler, identified as CVE-2026-88771 and CVE-2026-88772, both with a CVSS score of 9.5. These vulnerabilities allow remote code execution and affect all default configurations of NetScaler ADC and…