CVE-2025-26817
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Apr 3, 2025
Updated: Apr 7, 2025
CWE ID 78
Summary
CVE-2025-26817 is a newly disclosed vulnerability affecting Netwrix Password Secure version 9.2.0.32454. The security flaw allows an attacker to execute OS commands via a specially crafted input, potentially leading to serious system compromise. Successful exploitation could result in unauthorized access to sensitive data or even complete system takeover. Users are strongly urged to apply the available patch as soon as possible to mitigate this risk. Netwrix has confirmed the issue and provided a solution to prevent further attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.