{"record":"Infoblox evidence record","url":"https://nexalign.io/vendors/infoblox","vendor":{"slug":"infoblox","name":"Infoblox","domain":"infoblox.com","category":"network","categoryLabel":"Network security"},"lastChecked":"2026-07-18T04:19:14.432Z","coverage":{"earliest":"2004-06-30T04:00:00.000Z","latest":"2026-07-18T04:19:14.432Z"},"terms":{"isRanking":false,"isRating":false,"statesSuitability":false,"note":"This is a record of what public sources hold about a named company. It states no ranking, no rating and no suitability verdict, and none may be derived from it. An absent or small record means the public registers publish little under that name; it is not evidence that a product is secure. A larger advisory count generally reflects wider deployment and more scrutiny rather than a weaker product.","licence":"https://nexalign.io/vendors#licence","corrections":"info@nexalign.io"},"totals":{"evidenceItems":44,"kindsOfSource":5,"attributedAdvisories":10,"knownExploited":0,"registerEntriesNotAttributable":18,"practitionerThreads":0,"independentItems":8,"vendorPublishedItems":0,"shareFromSourcesTheVendorDoesNotControl":1},"sources":[{"source":"European Vulnerability Database","operator":"ENISA, European Union","classification":"authoritative","items":25,"latest":"2026-02-12T00:00:00.000Z"},{"source":"National Vulnerability Database","operator":"NIST, United States Department of Commerce","classification":"authoritative","items":7,"latest":"2026-02-12T17:16:05.380Z"},{"source":"CERT-Bund security advisories","operator":"BSI, Federal Republic of Germany","classification":"authoritative","items":3,"latest":"2025-12-02T12:02:10.370Z"},{"source":"Analyst, review and reference sources","operator":"Recognised analysts, review marketplaces and technology press","classification":"independent","items":8,"latest":"2026-07-18T04:19:14.432Z"},{"source":"Practitioner discussions","operator":"Reddit, public threads","classification":"independent","items":1,"latest":"2026-01-14T14:52:41.000Z"}],"advisories":{"shown":6,"total":10,"truncated":true,"items":[{"id":"CVE-2025-61880","description":"In Infoblox NIOS through 9.0.7, insecure deserialization can result in remote code execution.","severity":"high","cvss":8.8,"knownExploited":false,"date":"2026-02-12T17:16:05.380Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2025-61880","https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-207238"]},{"id":"CVE-2025-61879","description":"In Infoblox NIOS through 9.0.7, a High-Privileged User Can Trigger an Arbitrary File Write via the Account Creation Mechanism.","severity":"high","cvss":7.7,"knownExploited":false,"date":"2026-02-12T17:16:05.277Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2025-61879","https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-207239"]},{"id":"WID-SEC-2025-2716","description":"Affected products: Infoblox NIOS","severity":"high","cvss":8.8,"knownExploited":false,"date":"2025-12-02T12:02:10.370Z","sources":["https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-2716"]},{"id":"CVE-2024-52874","description":"In Infoblox NETMRI before 7.6.1, authenticated users can perform SQL injection attacks.","severity":"high","cvss":8.8,"knownExploited":false,"date":"2025-05-22T18:15:40.543Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2024-52874","https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-16187"]},{"id":"CVE-2025-32815","description":"An issue was discovered in Infoblox NETMRI before 7.6.1.","severity":"medium","cvss":6.5,"knownExploited":false,"date":"2025-05-22T15:16:04.750Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2025-32815","https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-16152"]},{"id":"CVE-2025-32814","description":"An issue was discovered in Infoblox NETMRI before 7.6.1.","severity":"critical","cvss":9.8,"knownExploited":false,"date":"2025-05-22T15:16:04.637Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2025-32814","https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-16146"]}]},"practitionerThreads":{"shown":0,"total":0,"truncated":false,"items":[]},"independentCoverage":{"shown":5,"total":8,"truncated":true,"items":[{"title":"Infoblox Reviews, Ratings & Features 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/market/security-threat-intelligence-products-and-services/vendor/infoblox","date":null},{"title":"Infoblox - Wikipedia","host":"en.wikipedia.org","url":"https://en.wikipedia.org/wiki/Infoblox","date":null},{"title":"What is your primary use case for Infoblox NIOS?","host":"peerspot.com","url":"https://www.peerspot.com/questions/what-is-your-primary-use-case-for-infoblox-nios","date":null},{"title":"What is your primary use case for Infoblox BloxOne Threat Defense?","host":"peerspot.com","url":"https://www.peerspot.com/questions/what-is-your-primary-use-case-for-infoblox-bloxone-threat-defense","date":null},{"title":"Infoblox Solutions and Reviews","host":"peerspot.com","url":"https://www.peerspot.com/vendors/infoblox","date":null}]},"vendorPublished":{"shown":0,"total":0,"truncated":false,"items":[]},"openQuestions":["A further 18 register entries mention Infoblox without naming a product of Infoblox as affected. They are excluded rather than counted as vulnerabilities.","No public practitioner discussion naming Infoblox was found in the indexed threads. Operational experience with this product is not represented in this record.","Pricing, contract terms, notice periods and support commitments are not part of any public register. They come from the vendor and belong in a negotiation record.","Certification status such as ISO 27001, SOC 2 or BSI C5 has to be checked against the current certificate and its stated scope. A valid certificate can still exclude the product being bought."]}