Netwrix develops a focused portfolio of identity and access governance tools—including Directory Manager, Auditor, and Password Secure—that operate across Active Directory and cloud environments to manage permissions and detect unauthorized activity. Vulnerabilities affecting the vendor skew strongly toward critical severity and recur through weakness classes including improper authentication, cross-site scripting, insecure deserialization, and permission-assignment flaws that are characteristic of identity-management software handling sensitive directory and credential data. The vendor's disclosures show a moderate tendency toward confirmed in-the-wild exploitation. Defenders should prioritize patches for this vendor's products, particularly those exposed to untrusted networks or federated identity flows; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Netwrix over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-31199CRITICAL Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting both the Netwrix Auditor server and agents installed on monitor | Nov 8, 2022 | 9.8 | 84 | YES | NO |
CVE-2025-26817CRITICAL Netwrix Password Secure 9.2.0.32454 allows OS command injection. | Apr 3, 2025 | 9.8 | 31 | NO | NO |
CVE-2023-41264CRITICAL Netwrix Usercube before 6.0.215, in certain misconfigured on-premises installations, allows authentication bypass on deployment endpoints, leading to privilege escalation. This onl | Nov 28, 2023 | 9.8 | 30 | NO | NO |
CVE-2025-48748CRITICAL Netwrix Directory Manager (formerly Imanami GroupID) through v.10.0.7784.0 has a hard-coded password. | May 29, 2025 | 10.0 | 27 | NO | NO |
CVE-2025-48749CRITICAL Netwrix Directory Manager (formerly Imanami GroupID) v11.0.0.0 and before & after v.11.1.25134.03 inserts Sensitive Information into Sent Data. | May 28, 2025 | 9.1 | 25 | NO | NO |
CVE-2025-26818CRITICAL Netwrix Password Secure through 9.2 allows command injection. | Apr 3, 2025 | 9.8 | 25 | NO | NO |
CVE-2019-14969HIGH Netwrix Auditor before 9.8 has insecure permissions on %PROGRAMDATA%\Netwrix Auditor\Logs\ActiveDirectory\ and sub-folders. In addition, the service Netwrix.ADA.StorageAuditService | Aug 12, 2019 | 7.8 | 25 | NO | NO |
CVE-2025-54392MEDIUM Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication error data, a different vulnerability than CVE-2025-47189. | Aug 7, 2025 | 6.1 | 23 | NO | NO |
CVE-2025-54395MEDIUM Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication configuration data. | Aug 7, 2025 | 6.1 | 22 | NO | NO |
CVE-2025-54393MEDIUM Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows Static Code Injection. Authenticated users can obtain administrative access. | Aug 7, 2025 | 5.4 | 21 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Netwrix.
Media articles that mention a CVE ID that affects a product developed by Netwrix — matched by CVE ID, not by vendor name.