Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Netwrix

First CVE: Aug 12, 2019Active for: 7 yearsTotal CVEs: 17
46.7
VTI Score
High

Netwrix develops a focused portfolio of identity and access governance tools—including Directory Manager, Auditor, and Password Secure—that operate across Active Directory and cloud environments to manage permissions and detect unauthorized activity. Vulnerabilities affecting the vendor skew strongly toward critical severity and recur through weakness classes including improper authentication, cross-site scripting, insecure deserialization, and permission-assignment flaws that are characteristic of identity-management software handling sensitive directory and credential data. The vendor's disclosures show a moderate tendency toward confirmed in-the-wild exploitation. Defenders should prioritize patches for this vendor's products, particularly those exposed to untrusted networks or federated identity flows; current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
17
Total CVEs
More Total CVEs than 95% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked vendors
5.9%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Netwrix over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 12, 2019
6 years ago
Most Recent CVE
Aug 7, 2025
352 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-31199CRITICAL
Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting both the Netwrix Auditor server and agents installed on monitor
Nov 8, 20229.884YESNO
CVE-2025-26817CRITICAL
Netwrix Password Secure 9.2.0.32454 allows OS command injection.
Apr 3, 20259.831NONO
CVE-2023-41264CRITICAL
Netwrix Usercube before 6.0.215, in certain misconfigured on-premises installations, allows authentication bypass on deployment endpoints, leading to privilege escalation. This onl
Nov 28, 20239.830NONO
CVE-2025-48748CRITICAL
Netwrix Directory Manager (formerly Imanami GroupID) through v.10.0.7784.0 has a hard-coded password.
May 29, 202510.027NONO
CVE-2025-48749CRITICAL
Netwrix Directory Manager (formerly Imanami GroupID) v11.0.0.0 and before & after v.11.1.25134.03 inserts Sensitive Information into Sent Data.
May 28, 20259.125NONO
CVE-2025-26818CRITICAL
Netwrix Password Secure through 9.2 allows command injection.
Apr 3, 20259.825NONO
CVE-2019-14969HIGH
Netwrix Auditor before 9.8 has insecure permissions on %PROGRAMDATA%\Netwrix Auditor\Logs\ActiveDirectory\ and sub-folders. In addition, the service Netwrix.ADA.StorageAuditService
Aug 12, 20197.825NONO
CVE-2025-54392MEDIUM
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication error data, a different vulnerability than CVE-2025-47189.
Aug 7, 20256.123NONO
CVE-2025-54395MEDIUM
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication configuration data.
Aug 7, 20256.122NONO
CVE-2025-54393MEDIUM
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows Static Code Injection. Authenticated users can obtain administrative access.
Aug 7, 20255.421NONO
View all 17 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products17 CVEs
53%
12%
35%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (5.9%)
Network16 (94.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None15 (88.2%)
Unknown0 (0.0%)
Required2 (11.8%)
Privileges Required
Low5 (29.4%)
High1 (5.9%)
None11 (64.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (17 CVEs).

CISA KEV
1 CVE
5.9% of CVEs· 100th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Netwrix.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Netwrix — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Netwrix's Products

View all 1 CNAs →

Top CWEs