Tenable Identity Exposure 2025 On-Premises Release Notes
These release notes are listed in reverse chronological order.
Tenable Identity Exposure 3.93.4 (2025-10-17)
 Enhancements
Enhancements
                                                            - 
                                                                        Improved system performance to provide consistent stability, particularly when you manage a high volume of data or tasks. 
 Bug Fixes
Bug Fixes
                                                            Tenable Identity Exposure version 3.93.4 contains the following bug fixes:
| Bug Fixes | 
|---|
| Tenable Identity Exposure fixed an issue in Regex that may prevent Cygni execution. | 
| Tenable Identity Exposure resolved an issue in the Resultant Set of Policy (RSoP) computation logic where certain RegistrySettings and FolderOptions are not considered. | 
| Tenable Identity Exposure resolved an issue where the HC-DOMAIN-REACHABILITY health check might incorrectly return a failure status. | 
| Tenable Identity Exposure now ensures that the encrypted SQL password is not exposed in the installer logs. | 
| Tenable Identity Exposure fixed the Tenable certificate persistence issue in the Group Policy Object (GPO). | 
| Tenable Identity Exposure resolved an issue where RabbitMQ queues could occasionally disconnect and fail to reconnect properly due to environmental or infrastructure factors. | 
 Updated Software Dependencies
Updated Software Dependencies
                                                            | Software Name | Pre-upgrade | Post-upgrade | 
|---|---|---|
| Tenable Identity Exposure | 3.93.3 | 3.93.4 | 
| C++ 2015-2022 Redistributable | 14.38.33135.0 | 14.38.33135.0 | 
| .NET Windows Server Hosting | 8.0.20.25420 | 8.0.21.25475 | 
| IIS URL Rewrite Module 2 | 7.2.1993 | 7.2.1993 | 
| Application Request Routing 3.0 | 3.0.5311 | 3.0.5311 | 
| NodeJS | 20.19.5.0 | 20.19.5.0 | 
| Erlang OTP | 26.2.5.15 | 26.2.5.15 | 
| Rabbit MQ | 4.0.9 | 4.0.9 | 
| SQL Server | 15.0.4445.1 | 15.0.4445.1 | 
| OpenSSL | 3.5 | 3.5 | 
| Envoy | 1.29.12 | 1.29.12 | 
| Handle | 5.0 | 5.0 | 
| Curl | 8.16.0 | 8.16.0 | 
Tenable Identity Exposure 3.93.3 (2025-09-24)
 New Feature
New Feature
                                                        - 
                                                                    New dashboard template—A new dashboard template helps organizations monitor and improve compliance with ACSC cybersecurity standards. It provides visibility into a recent "Five Eyes" alliance report on detecting and mitigating Active Directory compromises, offering both a high-level overview and detailed insights to help you prioritize remediation. 
 Enhancements
Enhancements
                                                        - 
                                                                    Improved IoA deployment process—Replaced the long command block in the scheduled task with a dedicated PowerShell script: - 
                                                                            Dedicated Listener Launcher: The new deployment uses a signed listener launcher.ps1 script, stored on the SYSVOL. This script simplifies the scheduled task and improves security. 
- 
                                                                            Certificate Deployment: The Tenable certificate is now deployed automatically via Group Policy (GPO), which is necessary for running the signed script. 
 
- 
                                                                            
- 
                                                                    RabbitMQ — Improved resilience by implementing automatic recovery for dropped connections, ensuring continuous message processing and preventing service interruptions. 
 Bug Fixes
Bug Fixes
                                                        Tenable Identity Exposure version 3.93.3 contains the following bug fixes:
| Bug Fixes | 
|---|
| The Indicator of Attack Brute Force now only displays the latest IP/Hostname source in the attack vector attributes. | 
| The Indicator of Attack Kerberoasting now successfully accommodates delays in Windows Event Log ingestion. | 
| The Indicator of Exposure Logon Restrictions for Privileged Users reason template is now enhanced to state explicitly that all IRSNB rights must be denied for privileged user accounts. | 
| The Secure Relay now automates the signing of scheduled task scripts, resolving issues with auto-updates that arose from recent security measures. This change reduces support cases and ensures updates run smoothly without manual fixes. | 
 Updated Software Dependencies
Updated Software Dependencies
                                                        | Software Name | Pre-upgrade | Post-upgrade | 
|---|---|---|
| Tenable Identity Exposure | 3.93.2 | 3.93.3 | 
| C++ 2015-2019 Redistributable | 14.38.33135.0 | 14.38.33135.0 | 
| .NET Windows Server Hosting | 8.0.16.25216 | 8.0.20.25420 | 
| IIS URL Rewrite Module 2 | 7.2.1993 | 7.2.1993 | 
| Application Request Routing 3.0 | 3.0.5311 | 3.0.5311 | 
| NodeJS | 20.19.4.0 | 20.19.5.0 | 
| Erlang OTP | 26.2.5.14 | 26.2.5.15 | 
| Rabbit MQ | 4.0.9 | 4.0.9 | 
| SQL Server | 15.0.4430.1 | 15.0.4445.1 | 
| OpenSSL | 3.5 | 3.5 | 
| Envoy | 1.29.12 | 1.29.12 | 
| Handle | 5.0 | 5.0 | 
| Curl | 8.13.0 | 8.16.0 | 
Tenable Identity Exposure 3.77.13 (2025-08-06)
 Bug Fixes
Bug Fixes
                                                        Tenable Identity Exposure version 3.77.13 contains the following bug fixes:
| Bug Fixes | 
|---|
| Tenable Identity Exposure improved the Erlang and RabbitMQ upgrade process to ensure all Erlang services are stopped and the installation directory is fully cleaned before reinstalling. This fixes a dependency issue that previously caused Security Engine Node installation or upgrade to fail. | 
| Tenable Identity Exposure now ensures consistent detection of the "Tenable.ad" Group Policy Object (GPO) during Indicators of Attack (IoA) deployment, even in complex Active Directory environments. This enhances the reliability of the IOA installation process. | 
 Updated Software Dependencies
Updated Software Dependencies
                                                        | Software Name | Pre-upgrade | Post-upgrade | 
|---|---|---|
| Tenable Identity Exposure | 3.77.12 | 3.77.13 | 
| C++ 2015-2019 Redistributable | 14.38.33135.0 | 14.38.33135.0 | 
| .NET Windows Server Hosting | 8.0.18.25317 | 8.0.18.25317 | 
| IIS URL Rewrite Module 2 | 7.2.1993 | 7.2.1993 | 
| Application Request Routing 3.0 | 3.0.5311 | 3.0.5311 | 
| NodeJS | 20.19.3.0 | 20.19.4.0 | 
| Erlang OTP | 26.2.5.13 | 26.2.5.14 | 
| Rabbit MQ | 4.0.9 | 4.0.9 | 
| SQL Server | 15.0.4430.1 | 15.0.4430.1 | 
| OpenSSL | 3.5 | 3.5.1 | 
| Envoy | 1.29.12 | 1.29.12 | 
| Handle | 5.0 | 5.0 | 
| Curl | 8.14.1 | 8.15.0 | 
Tenable Identity Exposure 3.93.2 (2025-08-05)
 Bug Fixes
Bug Fixes
                                                        Tenable Identity Exposure version 3.93.2 contains the following bug fixes:
| Bug Fixes | 
|---|
| Tenable Identity Exposure improved the Erlang and RabbitMQ upgrade process to ensure all Erlang services are stopped and the installation directory is fully cleaned before reinstalling. This fixes a dependency issue that previously caused Security Engine Node installation or upgrade to fail. | 
| Tenable Identity Exposure now ensures consistent detection of the "Tenable.ad" Group Policy Object (GPO) during Indicators of Attack (IoA) deployment, even in complex Active Directory environments. This enhances the reliability of the IOA installation process. | 
| The Indicator of Exposure Managed Service Accounts Dangerous Misconfigurations now whitelists correctly trustees belonging to a group. | 
| The Indicator of Exposure Logon Restrictions for Privileged Users reason template is now enhanced to state explicitly that all IRSNB rights must be denied for privileged user accounts. | 
| Tenable Identity Exposure fixed a rare memory leak in the Data Collector. | 
| Tenable Identity Exposure now successfully recovers from network disruptions and resumes IoA processing. | 
| The IoA Password Guessing now correctly displays vector attributes, even when some hostnames are unknown. | 
| Tenable Identity Exposure fixed an issue where the msds-behavior-version LDAP attribute was not properly decoded for Windows Server 2025. | 
 Updated Software Dependencies
Updated Software Dependencies
                                                        | Software Name | Pre-upgrade | Post-upgrade | 
|---|---|---|
| Tenable Identity Exposure | 3.93 | 3.93.2 | 
| C++ 2015-2019 Redistributable | 14.38.33135.0 | 14.38.33135.0 | 
| .NET Windows Server Hosting | 8.0.16.25216 | 8.0.16.25216 | 
| IIS URL Rewrite Module 2 | 7.2.1993 | 7.2.1993 | 
| Application Request Routing 3.0 | 3.0.5311 | 3.0.5311 | 
| NodeJS | 20.19.2.0 | 20.19.4.0 | 
| Erlang OTP | 26.2.5.12 | 26.2.5.14 | 
| Rabbit MQ | 4.0.3 | 4.0.9 | 
| SQL Server | 15.0.4430.1 | 15.0.4430.1 | 
| OpenSSL | 3.5 | 3.5 | 
| Envoy | 1.29.12 | 1.29.12 | 
| Handle | 5.0 | 5.0 | 
| Curl | 8.13.0 | 8.13.0 | 
Tenable Identity Exposure 3.77.12 (2025-07-21)
 New Features
New Features
                                                        - 
                                                                    SMTP OAuth Alerting—New support for OAuth, Microsoft 365’s modern and secure authentication protocol for alerting features. For more information, see Microsoft 365 SMTP OAuth Configuration in the Tenable Identity Exposure User Guide. 
 Bug Fixes
Bug Fixes
                                                        Tenable Identity Exposure version 3.77.12 contains the following bug fixes:
| Bug Fixes | 
|---|
| For SQL upgrades, the installation verifies whether the current user has the following rights :SeBackupPrivilege, SeDebugPrivilege, and SeSecurityPrivilege. | 
| The Secure Relay now connects only to the Domain Controller (DC) specified in the interface and ignores any redirects from the contacted DC. | 
| The Dynamic RPC port reason has fully migrated to the Domain Data Collection Health Check. | 
| Alert email links now point to expected pages in all cases. | 
| The Indicator of Attack Password Guessing now reports "Data not available" when it cannot obtain the source IP from the "Workstation" value. | 
| The Relay now resubscribes to SMB events when it receives the Win32 error "The account is not authorized to log on from this station." | 
| Tenable Identity Exposure improved the resilience of RabbitMQ queues when a third-party tool causes an issue. | 
| Tenable Identity Exposure now supports custom naming for the Indicator of Attack (IoA) GPO. Customers who previously used a custom IoA GPO name should reinstall the IoA using the latest IoA script. | 
| The Health Check reason "Working Connection to the Dynamic RPC Port" has relocated to the Privileged Analysis Health Check. | 
| Tenable Identity Exposure user interface renamed "Edit" buttons to "Save" to make modification actions more explicit. | 
| Removal of the constraint that prevented the unselecting of all domains in the IoA configuration, eliminating Health Check errors caused by missing GPOs. | 
| The IoA script now refreshes IoA GPO computer settings only during installation, eliminating the need for user interaction. | 
| The NTDS Extraction Indicator of Attack (IoA) now correctly resolves the source attack vector attribute Username. | 
| Tenable Identity Exposure only displays an error message on the console during the final retry attempt of the GPO import step in the IOA installation script. | 
| Tenable Identity Exposure improved input search isolation between the Domains and Honey Account pages. | 
| The reason "GPO parameter password is missing" from the Application of Weak Password Policies on Users Indicator of Exposure (IoE) no longer reports a false positive deviance on the domain's Policies folder. | 
| Tenable Identity Exposure fixed a rare memory leak in the Data Collector. | 
| Tenable Identity Exposure now successfully recovers from network disruptions and resumes IoA processing. | 
| The IoA Password Guessing now correctly displays vector attributes, even when some hostnames are unknown. | 
| Tenable Identity Exposure fixed an issue where the msds-behavior-version LDAP attribute was not properly decoded for Windows Server 2025. | 
| The Indicator of Attack BruteForce now displays the source IP Address in the correct format. | 
| Tenable Identity Exposure improved the IOA event log ingestion speed, lowering event loss probability, thus decreasing the number of false positives and false negatives. | 
| The domain connectivity test and Privileged Analysis health checks now properly handle specific objectSID encoding. | 
| The Indicator of Attack NTDS Extraction now properly correlates the source username. | 
| The Security Engine Node service 'Cygni' now starts successfully even when there is no internet connection while the OpenTelemetry feature is enabled. | 
| The feature to export IoA to PDF now functions correctly. | 
| Tenable Identity Exposure resolved an issue where triggering a group policy update could cause the Tenable Event Logs listener to stall while awaiting interactive user input. | 
 Updated Software Dependencies
Updated Software Dependencies
                                                        | Software Name | Pre-upgrade | Post-upgrade | 
|---|---|---|
| Tenable Identity Exposure | 3.77.11 | 3.77.12 | 
| C++ 2015-2019 Redistributable | 14.38.33135.0 | 14.38.33135.0 | 
| .NET Windows Server Hosting | 8.0.15.25165 | 8.0.18.25317 | 
| IIS URL Rewrite Module 2 | 7.2.1993 | 7.2.1993 | 
| Application Request Routing 3.0 | 3.0.5311 | 3.0.5311 | 
| NodeJS | 20.19.0 | 20.19.3.0 | 
| Erlang OTP | 26.2.5.11 | 26.2.5.13 | 
| Rabbit MQ | 4.0.3 | 4.0.9 | 
| SQL Server | 15.0.4430.1 | 15.0.4430.1 | 
| OpenSSL | 3.5 | 3.5 | 
| Envoy | 1.29.12 | 1.29.12 | 
| Handle | 5.0 | 5.0 | 
| Curl | 8.13.0 | 8.14.1 | 
Tenable Identity Exposure 3.93 (2025-06-30)
 New Features
New Features
                                                        - 
                                                                    Exposure Center—A feature that enhances your organization's identity security posture. It identifies weaknesses and misconfigurations across your identity risk surface, covering both the underlying identity systems, such as Entra ID, and the identities within those systems. - 
                                                                            The Exposure Overview feature works with Active Directory and/or Entra ID data. 
- 
                                                                            The Exposure Instances feature currently works only with Entra ID data. 
 
- 
                                                                            
- 
                                                                    Identity 360—A new identity-centric feature delivers a comprehensive inventory of all identities across your organization's identity risk surface. It unifies identities from both Active Directory and Entra ID, enabling you to evaluate and rank them by risk to quickly identify and prioritize the most vulnerable identities in your environment. - 
                                                                            The Identity 360 feature works with Active Directory and/or Entra ID data. 
 Tip: To use Tenable cloud-based features, you must activate specific settings to share data to the Tenable cloud for analysis. See Identity 360, Exposure Center, and Microsoft Entra ID Support Activation and Tenable Cloud Data Collection for instructions.
- 
                                                                            
Active Directory (AD) Indicators of Exposure (IoE)
- 
                                                                    Sensitive Exchange Permissions — This IoE manages permissions related to Exchange groups and resources within the domain. It now shows exclusively all permissions either originating from or targeting Exchange to enhance readability in other IoEs. 
- 
                                                                    Exchange Group Members — This IoE tracks members of sensitive Exchange groups. 
- 
                                                                    Unsupported or Outdated Exchange Servers — This IoE detects outdated Exchange servers that Microsoft no longer supports as well as those missing the latest Cumulative Updates. To maintain a secure and fully supported Exchange environment, promptly address obsolete or unpatched servers. Failure to do so increases the risk of exploitation, exposing your organization to data breaches and ransomware attacks. 
- 
                                                                    Exchange Dangerous Misconfigurations to list misconfigurations that impact Exchange resources or its underlying Active Directory schema objects. 
- 
                                                                    Exchange Group Members — This IoE tracks members of sensitive Exchange groups. 
- 
                                                                    ADCS Dangerous Misconfigurations — This IoE identifies issuance policies (enterprise OIDs) that allow principals to become member of AD groups implicitly. 
- 
                                                                    Domain Without Computer-Hardening GPOs — This IoE checks the GPO setting "Block NTLM over SMB". 
Other Features
- 
                                                                    Health Check — A new domain health check enhances confidence in your Indicator of Attack deployment by identifying and addressing known errors on a per-domain basis. For more information, refer to Health Checks in the Tenable Identity Exposure User Guide. 
- 
                                                                    Usability — Tenable Identity Exposure now helps customers get visibility on the recent report by the "5 eyes" or their civilian agencies. 
 Enhancements
Enhancements
                                                        Indicators of Exposure
- 
                                                                    Single Member AD / Entra Group — The IoE now shows the group member in the "Why it matters" description. 
- 
                                                                    First-Party Service Principal With Credentials — The IoE now shows the details for the identified credentials in the "Why it matters" description. 
- 
                                                                    Single Member AD / Entra Group and Empty Group — These IoEs now only count direct members for more accurate and meaningful results. 
- 
                                                                    Mapped Certificates on Accounts - 
                                                                            This IoE now reports weak explicit certificate mappings, addressing the AD CS ESC14 Abuse Technique. 
- 
                                                                            This IoE previously reported privileged users with only two types of mappings: X509IssuerSubject and X509SubjectOnly. It has now expanded its original scope to include additional mappings — X509RFC822, X509IssuerSerialNumber, X509SKI, and X509SHA1PublicKey. 
 
- 
                                                                            
- 
                                                                    Domain Without Computer-Hardening GPOs — New checks related to the Windows Defender Credential Guard security feature, used to protect in-memory credentials. 
- 
                                                                    Ensure SDProp Consistency — Improved recommendations. 
- 
                                                                    Shadow Credentials — Improved recommendations for remediation of Return of Coppersmith’s Attack (ROCA). Introduction of a new option to remove potential false positives related to hybrid environments with Entra ID when the "device writeback" feature is disabled. This has an impact on the "Orphan Key Credential" reason in this IoE. 
- 
                                                                    Managed Service Accounts Dangerous Misconfigurations — Improvement in this IoE to include support for groups, enabling streamlined control of access to a gMSA. 
- 
                                                                    Security Profile Customization — Improved description for the options "Permitted object owner (by group membership)" for applicable IoEs. 
- 
                                                                    Two new options to enhance control over object ownership and permissions by group membership: - 
                                                                            Permitted Object Owner (by Group Membership): Allows security principals to be designated as object owners through their group membership. 
- 
                                                                            Permitted Trustees List (by Group Membership): Enables the assignment of special permissions to security principals based on their group membership. 
 
- 
                                                                            
- 
                                                                    Unsecured Configuration of Netlogon Protocol - Tenable Identity Exposure now sets the default value of the "Skip registry key check" option to "true". This change assumes that users have applied the February 9, 2021 updates. This modification applies only to the default profile, leaving custom profiles unaffected. 
- 
                                                                    Password Management Risk — Added the Detection of Password Weaknesses IoE widget into the dashboard template. 
- 
                                                                    Root Objects Permissions Allowing DCSync-Like Attacks — Now includes a new option, "Keep MSOL_* accounts," which allows you to exclude those accounts and reduce false positives. By default, this option is disabled in the security profile, so the IOE does not flag MSOL_* accounts as deviant. 
Indicators of Attack
- 
                                                                    Golden Ticket IoA— Improved attack vector text. 
- 
                                                                    DCSync does not trigger an alert if its source comes from a username with a prefix MSOL_ (hardcoded and valid for basic mode only). 
- 
                                                                    Enumeration of Local Administrators does not trigger an alert if the target IP is unknown. 
- 
                                                                    Golden Ticket only triggers an alert if an attacker authenticated after forging a TGT (basic mode only). 
- 
                                                                    OS Credential Dumping: LSASS Memory does not trigger an alert if the tool belongs to Arctic Wolf Network (basic mode only). 
- 
                                                                    These IoAs no longer trigger alerts in the following cases: - 
                                                                            DC Sync— When the source is a user or hostname related to the Azure ADConnect tool (basic mode only). 
- 
                                                                            NTDS Extraction — When the source tool is either VSS Requestor or Veeam (legitimate backup tools). 
- 
                                                                            Enumeration of Local Administrators — When the IoA cannot find the source user SID (basic mode only). 
- 
                                                                            Petit Potam — When the IoA cannot retrieve the associated logon event. 
- 
                                                                            Golden Ticket — When the IoA cannot fetch the source vectors (basic mode only). 
 
- 
                                                                            
Other Enhancements
- 
                                                                    Identity 360 and Exposure Overview now redirect to the Exposure Instances page when drilling down on the related weaknesses 
- 
                                                                    Trust Attributes and Types in Directory Services - 
                                                                            The trustType attribute now supports the TTAAD (TRUST_TYPE_AAD) value. 
- 
                                                                            The trustAttributes attribute now supports the TDAV (TRUST_ATTRIBUTE_DISABLE_AUTH_TARGET_VALIDATION) value. 
 
- 
                                                                            
- Tenable One Container Change — To ensure an optimal product experience, Tenable Identity Exposure now prevents switching to a different Tenable One container when you upload a new license file.
- 
                                                                    Export function — Users can choose the separator (comma or semicolon) when performing a CSV export, enabling flexibility to suit various use cases. The browser remembers the last used separator for future exports. 
- 
                                                                    Identity 360 — Improved loading time for pages, such as asset details in the Access & Entitlement tabs. 
- 
                                                                    Permissions to Collect the AD Domain Data — Now hides the "Granted Permissions to Collect Privileged Data" details when Privileged Analysis is deactivated in the user interface. Make sure your Relay is up to date for this feature to work. 
 Bug Fixes
Bug Fixes
                                                        Tenable Identity Exposure version 3.93 contains the following bug fixes:
| Bug Fixes | 
|---|
| Tenable Identity Exposure addressed the missing data timeframe setting in the report configuration. | 
| The Domain Controller Activity health check now detects inactive Domain Controllers within a 15-minute window based on Indicator of Attack event log activity. While it still waits for this duration before reporting failures, it now reports successful cases and reactivated Domain Controllers much faster. Additionally, a bug fix ensures the health check uses up-to-date data. | 
| Hyperlink text descriptions in Exposure Instances now wrap to the next line when they exceed the available space. | 
| Identity 360 CSV exports now handle data containing double quotes correctly. | 
| The context-sensitive help badges (book icons) to access the user documentation are now visible. | 
| Tenable Identity Exposure shows the domains to which alerts are attached in the web interface. | 
| The health check for the Data Collector/Relay versions is now considered healthy (green) if the Relay and data collector versions match in both the major and minor updates, or if they only differ by one in the minor version. This gives some flexibility for automatic updates or when the software update is slightly ahead of the platform during rollouts. | 
| Tenable Identity Exposure improved websockets security. | 
| The "Unsafe permissions set on the computer object" reason in the Local Administrative Account Management IoE now appears correctly in non-US English languages. | 
| Identities with accounts on multiple configured Tenable Identity Exposure tenants (AD directories or Entra ID tenants) no longer disappear from the list of identities. | 
| When platforms require a Secure Relay, the LDAP and SMTP configurations now enforce the selection of a specific Secure Relay to use. | 
| When Tenable Identity Exposure is configured to appear in Spanish, Entra ID IoE descriptions appear in U.S. English. | 
| Tenable Identity Exposure resolved the loading error in Identity Explorer. | 
| Tenable Identity Exposure enhanced the loading performance of the Attack Alert blade. | 
| The option 'Permitted trustees list' now allows the use of the SID format of an account in addition to the previous format (DN format). | 
| The decoder for the dnsProperty attribute now accurately parses the binary data associated with dynamic updates. | 
| Tenable Identity Exposure raised RMQ memory limit to prevent performance slowdown. | 
| Tenable Identity Exposure now ensures header visibility remains intact after login. | 
| Tenable Identity Exposure reduced 504 errors between the Secure Relay and the Directory Listener to enhance performance and prevent product disruptions. | 
| Pendo features are now active in certain Tenable Identity Exposure environments. | 
| Tenable Identity Exposure improved the display of samAccountName and made it searchable. | 
| Tenable Identity Exposure added more contextual information related to LDAP login issues. | 
| Tenable Identity Exposure resolved the issue with unwanted redirections while using the web interface. | 
| Tenable now digitally signs the script to configure Indicators of Attack, preventing external security tools from flagging it as a potential risk due to a missing signature. | 
| Deleted/Disabled Computer/Users no longer generate deviances if you did not explicitly set the "Keep Deleted" or "Keep Disabled" options to true in your security profiles. | 
| In the event of an upgrade failure, Tenable Identity Exposure's rollback mechanism now correctly reverts the system to its previous state. 
 Tip: To ensure a successful rollback, Tenable recommends allowlisting the Rollback.exe located in the Backups_Tenable folder. Alternatively,  allowlist the entire Backups_Tenable folder to prevent interference from antivirus or EDR solutions. | 
 Updated Software Dependencies
Updated Software Dependencies
                                                        | Software Name | Pre-upgrade | Post-upgrade | 
|---|---|---|
| Tenable Identity Exposure | 3.77.11 | 3.93 | 
| C++ 2015-2019 Redistributable | 14.38.33135.0 | 14.38.33135.0 | 
| .NET Windows Server Hosting | 8.0.15.25165 | 8.0.16.25216 | 
| IIS URL Rewrite Module 2 | 7.2.1993 | 7.2.1993 | 
| Application Request Routing 3.0 | 3.0.5311 | 3.0.5311 | 
| NodeJS | 20.19.0 | 20.19.2.0 | 
| Erlang OTP | 26.2.5.11 | 26.2.5.12 | 
| Rabbit MQ | 4.0.3 | 4.0.3 | 
| SQL Server | 15.0.4430.1 | 15.0.4430.1 | 
| OpenSSL | 3.5 | 3.5 | 
| Envoy | 1.29.12 | 1.29.12 | 
| Handle | 5.0 | 5.0 | 
| Curl | 8.13.0 | 8.13.0 | 
Tenable Identity Exposure 3.77.11 (2025-04-30)
Tenable has identified and addressed a critical vulnerability (CVE-2025-32433) affecting the SSH implementation in Erlang/OTP, where a flaw in the handling of SSH protocol messages allows a malicious actor to gain unauthorized access and execute arbitrary code without valid credentials.
 Updated Software Dependencies
Updated Software Dependencies
                                                        | Software Name | Pre-upgrade | Post-upgrade | 
|---|---|---|
| Tenable Identity Exposure | 3.77.10 | 3.77.11 | 
| C++ 2015-2019 Redistributable | 14.38.33135.0 | 14.38.33135.0 | 
| .NET Windows Server Hosting | 8.0.14.25112 | 8.0.15.25165 | 
| IIS URL Rewrite Module 2 | 7.2.1993 | 7.2.1993 | 
| Application Request Routing 3.0 | 3.0.5311 | 3.0.5311 | 
| NodeJS | 20.18.3.0 | 20.19.0 | 
| Erlang OTP | 26.2.5.6 | 26.2.5.11 | 
| Rabbit MQ | 4.0.3 | 4.0.3 | 
| SQL Server | 15.0.4430.1 | 15.0.4430.1 | 
| OpenSSL | 3.3.2 | 3.5 | 
| Envoy | 1.29.12 | 1.29.12 | 
| Handle | 5.0 | 5.0 | 
| Curl | 8.12.1 | 8.13 | 
Tenable Identity Exposure 3.77.10 (2025-03-27)
 Bug Fixes
Bug Fixes
                                                        Tenable Identity Exposure version 3.77.10 contains the following bug fixes:
| Bug Fixes | 
|---|
| The Indicator of Attack (IoA) listener now efficiently releases memory, correcting an issue introduced in version 3.77.8. This only affects customers who installed IoAs in versions 3.77.8 or 3.77.9 These customers must reinstall IoAs in version 3.77.10. | 
| Tenable Identity Exposure corrected the severity of the SAM Name Impersonation Indicator of Attack (IoA), which is classified as "Critical" but was mistakenly labeled as "High" in certain metadata. | 
| Tenable Identity Exposure updated the end-of-life dates for the latest Windows 11 versions. | 
| Windows Server 2025, released in November 2024, introduced a new AD functional level (the first since Server 2016), which the Domains with an Outdated Functional Level Indicator of Exposure (IoE) now takes into account. Tenable Identity Exposure also added expiration information for Server 2025 in the Computers Running an Obsolete OS IoE and made other minor adjustments across various IoEs (e.g., new schema version). Note: This does not confirm compatibility for hosting Tenable Identity Exposure on Windows Server 2025. Refer to future documentation updates or release notes for compatibility details. | 
| After deleting an object identified as deviant in the Logon Restrictions for Privileged Users IoE, the associated deviance closes correctly. | 
| Tenable Identity Exposure now ensures the proper removal of the Envoy service during the uninstallation of the Secure Relay, even when it's installed with Directory Listener. | 
| Tenable Identity Exposure now correctly handles event number 4624 in the latest version of Windows. | 
| Uninstalling the Secure Relay no longer removes the "Tools" folder shared with the Directory Listener. When both are installed on the same machine, the "Tools" folder now remains intact, preserving the nssm binary. | 
| Tenable Identity Exposure enhanced the uninstallation process by adding safeguards during upgrades to reduce rollbacks and improve system stability. | 
| Tenable Identity Exposure now properly applies selected reason filtering when selecting deviant objects (when applicable). | 
| When an attacker machine leaves a domain, the DCSync IoA can now raise alerts in basic mode. | 
| Tenable now digitally signs the script to configure Indicators of Attack, preventing external security tools from flagging it as a potential risk due to a missing signature. | 
| After upgrading, the Directory Listener prevents the installation of another Secure Relay on the same machine. | 
| Tenable Identity Exposure enhanced application resilience with proper handling of RabbitMQ channel errors during message publishing. | 
| The Domain Reachability health check now gives a more precise reason why the domain is unreachable. | 
 Updated Software Dependencies
Updated Software Dependencies
                                                        | Software Name | Pre-upgrade | Post-upgrade | 
|---|---|---|
| Tenable Identity Exposure | 3.77.9 | 3.77.10 | 
| C++ 2015-2019 Redistributable | 14.38.33135.0 | 14.38.33135.0 | 
| .NET Windows Server Hosting | 8.0.12.24603 | 8.0.14.25112 | 
| IIS URL Rewrite Module 2 | 7.2.1993 | 7.2.1993 | 
| Application Request Routing 3.0 | 3.0.5311 | 3.0.5311 | 
| NodeJS | 20.18.2.0 | 20.18.3.0 | 
| Erlang OTP | 26.2.5.6 | 26.2.5.6 | 
| Rabbit MQ | 4.0.3 | 4.0.3 | 
| SQL Server | 15.0.4415.2 | 15.0.4430.1 | 
| OpenSSL | 3.3.2 | 3.3.2 | 
| Envoy | 1.29.12 | 1.29.12 | 
| Handle | 5.0 | 5.0 | 
| Curl | 8.12.0 | 8.12.1 | 
Tenable Identity Exposure 3.77.9 (2025-02-20)
 Enhancement
Enhancement
                                                        - 
                                                                    Tenable Identity Exposure streamlined the rollback process to effectively revert the environment to its previous state, ensuring no residual clutter or inconsistencies remain. New Prerequisite: Ensure the storage manager has at least 20 GB of available disk space before initiating the rollback procedure. For information, see Resource Sizing in the Tenable Identity Exposure User Guide. 
 Bug Fixes
Bug Fixes
                                                        Tenable Identity Exposure version 3.77.9 contains the following bug fixes:
| Bug Fixes | 
|---|
| The audit.csv file from the IoA listener module installs correctly. | 
| Tenable Identity Exposure improved the retrieval method for the install location and ensured that all Cleanup_* custom actions do not cause installation or upgrade failures if they return an error. Additionally, Tenable Identity Exposure enforced non-interactive execution for custom actions to prevent confirmation prompts during installation. | 
| Tenable Identity Exposure enhanced application resilience with proper handling of RabbitMQ channel errors during message publishing. | 
| Tenable Identity Exposure enhanced the access list permissions of the updater folder to prevent access by any malicious users. | 
| Tenable Identity Exposure resolved a broken authorization schema in the Indicator of Attack script and configuration. | 
| Tenable Identity Exposure addressed a Credential Disclosure vulnerability to prevent administrators from extracting stored SMTP account credentials. | 
| The GoldenTicket Indicator of Attack (IoA) now raises an alert when the attacker uses the forged TGT ticket in basic mode. | 
| The Dangerous Kerberos Delegation Indicator of Exposure (IoE) now includes all incriminating attributes relative to orphaned SPN. | 
| Tenable Identity Exposure now prevents unauthenticated calls with internal services from being saved in activity logs, ensuring clearer and more accurate log records. | 
| Tenable Identity Exposure autocompletes the Security Engine Node (SEN) IP address with the fully qualified domain name (FQDN) when the customer's certificates contain only DNS names. | 
| Tenable Identity Exposure improved the Windows event log parsing speed, preventing the product from accumulating lag. You must redeploy Indicators of Attack to benefit from this change. | 
| Tenable Identity Exposure resolved environment variables restoration when upgrading the Security Engine Node (SEN). | 
| Tenable Identity Exposure now terminates the previous updater.exe process using a scheduled task during auto-update. | 
| The Tenable Identity Exposure name appears correctly in the user interface. | 
| The OS Credentials Dumping IoA now correctly resolves source IP, source hostname, and target IP when the attack is triggered by NTAUTHORITY\SYSTEM. | 
| Tenable Identity Exposure now considers the list of privileged PSOs from security profiles, resolving the IoE Application of Weak Password Policies on Users with the reason "No privileged PSOs are applied on the domain" when this option is configured. | 
| Tenable Identity Exposure resolved the handling of the lockout threshold and lockout duration options in the Application of Weak Password Policies on Users IoE. It is now possible to allowlist deviances when you set their values to 0. | 
| The Health Check page now displays even if one of the registered forests contains a backslash in the user name. | 
| Tenable Identity Exposure no longer prevents crawling from succeeding if the sensitive data collection isn't properly configured. | 
 Updated Software Dependencies
Updated Software Dependencies
                                                        | Software Name | Pre-upgrade | Post-upgrade | 
|---|---|---|
| Tenable Identity Exposure | 3.77.6 | 3.77.9 | 
| C++ 2015-2019 Redistributable | 14.38.33135.0 | 14.38.33135.0 | 
| .NET Windows Server Hosting | 8.0.11.24521 | 8.0.12.24603 | 
| IIS URL Rewrite Module 2 | 7.2.1993 | 7.2.1993 | 
| Application Request Routing 3.0 | 3.0.5311 | 3.0.5311 | 
| NodeJS | 20.18.1.0 | 20.18.2.0 | 
| Erlang OTP | 26.2.5.5 | 26.2.5.6 | 
| Rabbit MQ | 4.0.3 | 4.0.3 | 
| SQL Server | 15.0.4405.4 | 15.0.4415.2 | 
| OpenSSL | 3.3.2 | 3.3.2 | 
| Envoy | 1.29.10 | 1.29.12 | 
| Handle | 5.0.0 | 5.0 | 
| Curl | 8.11.0 | 8.12.0 |