ADV-2026-009 - Apache Log4j Vulnerabilities in Netwrix Access Analyzer

Executive Summary

The Sensitive Data Discovery (SDD) module in Netwrix Access Analyzer incorporates Apache Log4j Core, a widely used Java logging library. Three recently disclosed vulnerabilities in Apache Log4j Core could allow a network-based attacker to intercept sensitive log communications, inject malicious content into log streams, or cause security-relevant log events to be silently lost. Netwrix has updated the bundled Apache Log4j Core component to version 2.25.4 to address these issues.

In Netwrix Access Analyzer 11.6, the SDD module is delivered by the NAA SDD Add-On installer. In version 12.0, the SDD module was incorporated directly into the main Access Analyzer component installers (NAA, FSAA Proxy, and SPAA Agent), and the standalone SDD Add-On was deprecated. Customers running either release should refer to the Official Fixes table to identify which components require updating.

Users of Netwrix Access Analyzer are advised to update all applicable components to the latest versions immediately. Netwrix is unaware of any evidence of active exploitation of these vulnerabilities.

Vulnerability

Title Affected Component Affected Versions CVSS 4.0 Score CVSS 3.1 Score (Base / Temporal) Description
Dependency on Vulnerable Third-Party Components (CVE-2026-34477, CVE-2026-34478, CVE-2026-34480) Netwrix Access Analyzer SDD Module See Official Fixes 6.9 7.5 / 7.5 The Netwrix Access Analyzer SDD module incorporates a version of Apache Log4j Core affected by three recently disclosed vulnerabilities. These could allow a network-based attacker to inject malicious content into log streams, intercept TLS-protected log communications, or cause security-relevant log events to be silently lost.

Exploitability

Factors such as whether details about the vulnerability are publicly known, whether an exploit is readily available, or whether adversaries are actively exploiting the vulnerability are valuable in making risk-based judgments about urgency and priority; customers should use the information below in making those decisions.

Title Publicly known? Exploit available? Actively exploited?
Dependency on Vulnerable Third-Party Components (CVE-2026-34477, CVE-2026-34478, CVE-2026-34480) Yes No No

Solution

All Netwrix Access Analyzer customers are advised to update all installed Access Analyzer components to the patched versions listed in the Official Fixes table below as soon as possible.

Upgrade instructions are available in the Netwrix Access Analyzer documentation.

Please contact the Netwrix technical support team should you need assistance.

Official Fixes

Updated software has been released containing official fixes for all listed vulnerabilities. All three vulnerabilities are addressed in each of the following component releases.

Component Affected Version Patched Version
Netwrix Access Analyzer 11.6 NAA SDD Add-On ≤ 11.6.0.23 11.6.0.24
Netwrix Access Analyzer 12.0 NAA Installer ≤ 12.0.0.1286 12.0.0.1287
Netwrix Access Analyzer 12.0 FSAA Proxy Installer ≤ 12.0.0.1264 12.0.0.1265
Netwrix Access Analyzer 12.0 SPAA Agent Installer ≤ 12.0.0.1260 12.0.0.1261

FAQ

  1. How do I determine the versions of installed Netwrix Access Analyzer components?

    The Access Analyzer application version can be found by navigating to Help > About within the Console. For installed component versions, right-click the relevant component DLL in the installation directory and select Properties > Details > File Version. For additional guidance, see the Netwrix Access Analyzer documentation.

  2. Do I need to update all components?

    Customers should update all applicable components for their installed version. In Access Analyzer 11.6, only the NAA SDD Add-On requires updating. In Access Analyzer 12.0, the SDD module is included in all main component installers, so the NAA Installer, FSAA Proxy Installer, and SPAA Agent Installer should each be updated. The patched version for each component is listed in the Official Fixes table above.

  3. Are there any configuration changes required after updating?

    No additional configuration changes are required. The fixes are automatically applied upon updating to the remediated versions.

Revisions

Updates to this advisory may be made as necessary. Information about each change will be published in the table below.

Revision Date Description
1 2026-07-14T12:00:00Z First published

Disclaimer

The information and materials included in or linked to this Security Advisory are provided on an “as-is” basis and without warranty of any kind, and we disclaim all representations and warranties of any kind, whether express or implied, including warranties of merchantability and fitness for a particular use. You acknowledge and agree that your use of the information and materials included in or linked to this Security Advisory are at your own risk.