CVE-2020-11518: Zohocorp ManageEngine Adselfservice Plus

Critical severity, CVSS 9.8. EPSS: 19.2% chance of exploitation in the next 30 days.

Zoho ManageEngine ADSelfService Plus before 5815 allows unauthenticated remote code execution.

Affected products

  • Zohocorp ManageEngine Adselfservice Plus: up to and including 5.7; version 5.8 only

Published 2020-04-04. Last modified 2026-06-17.