THE article discusses a security vulnerability in the cloud-based "Passportal" password manager by N-able, which allows malicious websites to access users' vaults due to its design flaws. After a disclosure on July 8, 2026, N-able quickly issued a patch to strengthen security; however, concerns remain due to continued reliance on server-side decryption without end-to-end encryption (E2EE).
This vulnerability enables attackers to steal entire vaults and could allow significant breaches in managed service providers (MSPs) who use Passportal. Users are cautioned about potential risks associated with cloud-based credential managers.