CVE-2026-75791
- EPSS 1.72%
- Veröffentlicht 22.09.2026 12:03:31
- Zuletzt bearbeitet 22.09.2026 19:32:25
Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to an authentication bypass vulnerability in the REST API.
CVE-2026-74849
- EPSS 4.61%
- Veröffentlicht 22.09.2026 11:55:32
- Zuletzt bearbeitet 23.09.2026 04:17:44
Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to a remote code execution vulnerability in the GINA client.
CVE-2026-3183
- EPSS 0.48%
- Veröffentlicht 21.07.2026 06:58:53
- Zuletzt bearbeitet 21.07.2026 18:34:20
Zohocorp ManageEngine ADSelfService Plus versions before 6524 are vulnerable to Multi Factor Authentication Bypass.
- EPSS 1.96%
- Veröffentlicht 23.06.2026 09:16:28
- Zuletzt bearbeitet 24.06.2026 17:16:56
In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by an unauthenticated user, leading to account takeover.
CVE-2026-2740
- EPSS 1.7%
- Veröffentlicht 21.05.2026 12:36:17
- Zuletzt bearbeitet 23.07.2026 16:10:00
Zohocorp ManageEngine ADSelfService Plus version before 6525, DataSecurity Plus before 6264 and RecoveryManager Plus before 6313 are vulnerable to Authenticated Remote code execution in the agent machines due to the bug in the 3rd party dependency.
CVE-2026-1367
- EPSS 7.44%
- Veröffentlicht 23.02.2026 06:54:25
- Zuletzt bearbeitet 15.04.2026 00:35:42
Zohocorp ManageEngine ADSelfService Plus versions 6522 and below are vulnerable to authenticated SQL Injection in the search report option.
CVE-2025-11250
- EPSS 1.44%
- Veröffentlicht 13.01.2026 13:35:18
- Zuletzt bearbeitet 29.01.2026 19:12:29
Zohocorp ManageEngine ADSelfService Plus versions before 6519 are vulnerable to Authentication Bypass due to improper filter configurations.
CVE-2025-3833
- EPSS 44.63%
- Veröffentlicht 14.05.2025 11:00:27
- Zuletzt bearbeitet 30.09.2025 15:05:27
Zohocorp ManageEngine ADSelfService Plus versions 6513 and prior are vulnerable to authenticated SQL injection in the MFA reports.
CVE-2025-1723
- EPSS 1.42%
- Veröffentlicht 03.03.2025 08:15:15
- Zuletzt bearbeitet 30.09.2025 15:01:26
Zohocorp ManageEngine ADSelfService Plus versions 6510 and below are vulnerable to account takeover due to the session mishandling. Valid account holders in the setup only have the potential to exploit this bug.
CVE-2024-27310
- EPSS 2.27%
- Veröffentlicht 27.05.2024 18:15:09
- Zuletzt bearbeitet 27.11.2024 16:25:10
Zoho ManageEngine ADSelfService Plus versions below 6401 are vulnerable to the DOS attack due to the malicious LDAP input.