CVE-2020-28653

CRITICAL EXPLOITED NUCLEI

ManageEngine OpManager < 125203 - Remote Code Execution via Smart Update Manager Servlet

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2020-28653 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 4 public exploits from researchers including tuo4n8, intrigueio, mr-r3bot, including a Metasploit module exploits/multi/http/opmanager_sumpdu_deserialization. A Nuclei detection template is also available.

AI-analyzed exploit summary The repository contains a functional exploit for CVE-2020-28653, targeting a deserialization vulnerability in AdventNet ManageEngine products (2016-2020). The exploit sends a crafted payload to trigger remote code execution via a vulnerable servlet endpoint.

Description

Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution via the Smart Update Manager (SUM) servlet.

Exploits (4)

nomisec WORKING POC 1 stars
by tuo4n8 · remote
https://github.com/tuo4n8/CVE-2020-28653

The repository contains a functional exploit for CVE-2020-28653, targeting a deserialization vulnerability in AdventNet ManageEngine products (2016-2020). The exploit sends a crafted payload to trigger remote code execution via a vulnerable servlet endpoint.

Classification
Working Poc 95%
Attack Type
Deserialization
Complexity
Moderate
Reliability
Reliable
Target: AdventNet ManageEngine (2016-2020, pre-patch)
No auth needed
Prerequisites: Network access to the target · Vulnerable version of ManageEngine
devstral-2 · analyzed Feb 19, 2026 Full analysis →
nomisec WORKING POC 1 stars
by intrigueio · remote
https://github.com/intrigueio/cve-2020-28653-poc

This repository contains a functional exploit PoC for CVE-2020-28653, a deserialization vulnerability in ManageEngine OpManager. The exploit uses ysoserial to generate a malicious payload that triggers a DNS lookup upon deserialization, confirming vulnerability.

Classification
Working Poc 95%
Attack Type
Deserialization
Complexity
Moderate
Reliability
Reliable
Target: ManageEngine OpManager
No auth needed
Prerequisites: ysoserial.jar · DNS listener (e.g., Burp Collaborator)
devstral-2 · analyzed Feb 19, 2026 Full analysis →
nomisec WORKING POC
by mr-r3bot · remote
https://github.com/mr-r3bot/ManageEngine-CVE-2020-28653

This repository contains a functional exploit for CVE-2020-28653, targeting ManageEngine OPManager. It includes a Java deserialization gadget (CommonsBeanutils1) and a Python script to deliver the payload via HTTP requests to vulnerable endpoints.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: ManageEngine OPManager
No auth needed
Prerequisites: Network access to the target · Vulnerable version of ManageEngine OPManager
devstral-2 · analyzed Feb 19, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by Johannes Moritz, Robin Peraglie, Spencer McIntyre · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/opmanager_sumpdu_deserialization.rb

This Metasploit module exploits a Java deserialization vulnerability in ManageEngine OpManager's Smart Update Manager component, allowing unauthenticated remote code execution (RCE) as SYSTEM/root. It supports multiple payload types and targets versions 12.1 to 12.5.328.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: ManageEngine OpManager 12.1 - 12.5.328
No auth needed
Prerequisites: Network access to port 8060 · Vulnerable version of OpManager
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

ManageEngine OpManager SumPDU 12.1 - 12.5.232 - Java Deserialization
CRITICALby iamnoooob,pdresearch
Shodan: http.title:"opmanager plus" || http.title:"opmanager"
FOFA: title="opmanager plus" || title="opmanager"

References (3)

Core 3
Core References

Scores

CVSS v3 9.8
EPSS 0.7870
EPSS Percentile 99.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2025-10-28
Status published
Products (1)
zohocorp/manageengine_opmanager 12.5 build125000 (50 CPE variants)
Published Feb 03, 2021
Tracked Since Feb 18, 2026