CVE-2025-11250: Zohocorp ManageEngine Adselfservice Plus

Critical severity, CVSS 9.1. EPSS: 1.6% chance of exploitation in the next 30 days.

Zohocorp ManageEngine ADSelfService Plus versions before 6519 are vulnerable to Authentication Bypass due to improper filter configurations.

Affected products

  • Zohocorp ManageEngine Adselfservice Plus: before 6.5 (fixed in 6.5); version 6.5 only

Published 2026-01-13. Last modified 2026-06-17.