CVE-2020-14008: Zohocorp ManageEngine Applications Manager

High severity, CVSS 7.2. EPSS: 39.6% chance of exploitation in the next 30 days.

Zoho ManageEngine Applications Manager 14710 and before allows an authenticated admin user to upload a vulnerable jar in a specific location, which leads to remote code execution.

Affected products

  • Zohocorp ManageEngine Applications Manager: up to and including 13.0; version 14.0 only

Published 2020-09-04. Last modified 2026-06-17.