Skip to main content

ManageEngine vulnerabilities

2 published alerts for Zoho ManageEngine.

Actively exploited (KEV)Ransomware

CVE-2022-47966

Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability

Zoho ManageEngine is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-47966). Multiple Zoho ManageEngine products contain an unauthenticated remote code execution vulnerability due to the usage of an outdated third-party dependency, Apache Santuario. CISA remediation due date: 2023-02-13. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-40539

Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability

Zoho ManageEngine is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-40539). Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.