Skip to content
CVSS 10.0CVSS 10.0 · CRITICAL

CVE-2026-6516

Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.

View on NVD

Analysis

Zohocorp ManageEngine ADAudit Plus presenta una vulnerabilidad critica de ejecucion remota de codigo sin autenticacion a traves de su API de agentes. Un atacante puede tomar control total del servidor afectado sin necesidad de credenciales previas aprovechando este fallo de inyeccion de comandos. Dada su gravedad de 10.0 en la escala CVSS, es imperativo actualizar a la version 8606 para proteger la infraestructura de auditoria de Active Directory.

Relevant roles

CyberSecurityBackendWindows

Severity

Score: 10.0(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: LOW
Weakness (CWE): CWE-78

EPSS

No EPSS score yet (CVE may be too fresh).

Technical description

Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.

Published: 7/23/2026, 6:17:02 PM
Last modified: 7/23/2026, 8:17:23 PM

References

HomeEventsBlogResourcesTeam