Critical N-Able PassPortal Extension Flaw Gives Attackers Full Password Vault Access

A critical vulnerability (CVE-2026-15580) in the N-Able PassPortal browser extension allowed attackers to hijack user password vaults by intercepting sensitive session tokens through unsafe cross-context communication. The security flaw, which affected over 73,000 users, was resolved when N-able released a patch that implements strict origin validation and message handling.

Edward Kiledjian @ekiledjian