CVE-2026-6516

CRITICAL

Zohocorp ManageEngine ADAudit Plus < 8606 - Remote Code Execution

Title source: rule
STIX 2.1

Description

Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.

Scores

CVSS v3 10.0
EPSS 0.0473
EPSS Percentile 90.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-78
Status published
Products (1)
Zohocorp/ManageEngine ADAudit Plus < 8606
Published Jul 23, 2026
Tracked Since Jul 23, 2026