CVE-2025-11248: Zohocorp ManageEngine Endpoint Central

Medium severity, CVSS 4.3. EPSS: 0.5% chance of exploitation in the next 30 days.

ZohoCorp ManageEngine Endpoint Central versions prior to 11.4.2528.05 are vulnerable to a sensitive information logging issue. An authenticated user with access to the logs could potentially obtain the sensitive agent token.

Affected products

  • Zohocorp ManageEngine Endpoint Central: before 11.4.2528.05 (fixed in 11.4.2528.05)

Published 2025-10-27. Last modified 2026-10-08.