Skip to content
CVSS 10.0CVSS 10.0 · CRITICAL

CVE-2026-6516

Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.

Ver en NVD

Análisis

Zohocorp ManageEngine ADAudit Plus presenta una vulnerabilidad critica de ejecucion remota de codigo sin autenticacion a traves de su API de agentes. Un atacante puede tomar control total del servidor afectado sin necesidad de credenciales previas aprovechando este fallo de inyeccion de comandos. Dada su gravedad de 10.0 en la escala CVSS, es imperativo actualizar a la version 8606 para proteger la infraestructura de auditoria de Active Directory.

Roles relevantes

CyberSecurityBackendWindows

Severidad

Puntaje: 10.0(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: LOW
Tipo de falla (CWE): CWE-78

EPSS

Sin puntaje EPSS aún (CVE muy reciente).

Descripción técnica

Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.

Publicada: 23/7/2026, 18:17:02
Última modificación: 23/7/2026, 20:17:23

Referencias

InicioEventosBlogRecursosEquipo