CVE-2025-11248: Zohocorp ManageEngine Endpoint Central
Medium severity, CVSS 4.3. EPSS: 0.5% chance of exploitation in the next 30 days.
ZohoCorp ManageEngine Endpoint Central versions prior to 11.4.2528.05 are vulnerable to a sensitive information logging issue. An authenticated user with access to the logs could potentially obtain the sensitive agent token.
Affected products
- Zohocorp ManageEngine Endpoint Central: before 11.4.2528.05 (fixed in 11.4.2528.05)
Published 2025-10-27. Last modified 2026-10-08.