ADV-2026-014 - .NET Vulnerabilities in Netwrix Access Analyzer FSAA Data Collector

Executive Summary

The Netwrix Access Analyzer FSAA (File System Access) Data Collector includes the Microsoft .NET 8.0 runtime. The Microsoft July 2026 .NET servicing update addresses 17 security vulnerabilities that could potentially result in remote code execution, elevation of privilege, security feature bypass, tampering, spoofing, or denial of service. Netwrix has updated the .NET runtime included with the FSAA Data Collector from version 8.0.23 to 8.0.29 to address these issues.

Because the .NET runtime is included with the FSAA Data Collector, updating the system-installed .NET runtime does not update the affected component. Users of Netwrix Access Analyzer are advised to update the FSAA Data Collector to the latest version immediately. Netwrix is unaware of any evidence of active exploitation of these vulnerabilities.

Vulnerability

Title Affected Component Affected Versions CVSS 4.0 Score CVSS 3.1 Score (Base / Temporal) Description
Dependency on Vulnerable Third-Party Components Netwrix Access Analyzer FSAA Data Collector >=12.0, <=12.0.1489.1950 8.7 8.8 / 7.7 The FSAA Data Collector includes a version of the Microsoft .NET 8.0 runtime affected by 17 publicly disclosed vulnerabilities.

Exploitability

Factors such as whether details about the vulnerability are publicly known, whether an exploit is readily available, or whether adversaries are actively exploiting the vulnerability are valuable in making risk-based judgments about urgency and priority; customers should use the information below in making those decisions.

Title Publicly known? Exploit available? Actively exploited?
Dependency on Vulnerable Third-Party Components Yes No No

Solution

All Netwrix Access Analyzer customers are advised to update all installed instances of the FSAA Data Collector versions >=12.0 to version 12.0.1489.1950 as soon as possible by applying the applicable installer listed in the Official Fixes table below.

Upgrade instructions are available in the Netwrix Access Analyzer documentation.

Please contact the Netwrix technical support team should you need assistance.

Official Fixes

Updated software has been released containing official fixes for all listed vulnerabilities.

Component Release Version
Netwrix Access Analyzer Installer 12.0.0.1300
Netwrix Access Analyzer FSAA Proxy Installer 12.0.0.1278

FAQ

  1. How do I determine the version of the installed FSAA Data Collector?

    The Access Analyzer application version can be found by navigating to Help > About within the Console. For the installed FSAA Data Collector version, right-click the relevant component binary in the installation directory and select Properties > Details > File Version. For additional guidance, see the Netwrix Access Analyzer documentation.

  2. Do I need to update all components?

    Only the FSAA Data Collector is affected by the vulnerabilities addressed in this advisory. The components can be updated through our cumulative update patch installer, which may include updates to other components that you are licensed for. If you wish to only update the FSAA data collector via a hotfix patch, please reach out to Customer Support.

  3. Are there any configuration changes required after updating?

    No additional configuration changes are required. The fixes are automatically applied upon updating to the remediated version.

Revisions

Updates to this advisory may be made as necessary. Information about each change will be published in the table below.

Revision Date Description
2 2026-08-18T15:40:00Z Updated affected versions
1 2026-08-18T12:00:00Z First published

Disclaimer

The information and materials included in or linked to this Security Advisory are provided on an “as-is” basis and without warranty of any kind, and we disclaim all representations and warranties of any kind, whether express or implied, including warranties of merchantability and fitness for a particular use. You acknowledge and agree that your use of the information and materials included in or linked to this Security Advisory are at your own risk.

An update was made to this advisory.

An update was made to this advisory.