CVE-2025-11669: Zohocorp ManageEngine Access Manager Plus
High severity, CVSS 8.1. EPSS: 0.8% chance of exploitation in the next 30 days.
Zohocorp ManageEngine PAM360 versions before 8202; Password Manager Pro versions before 13221; Access Manager Plus versions prior to 4401 are vulnerable to an authorization issue in the initiate remote session functionality.
Affected products
- Zohocorp ManageEngine Access Manager Plus: before 4.4 (fixed in 4.4); version 4.4 only
- Zohocorp ManageEngine PAM360: before 8.2 (fixed in 8.2); version 8.2 only
- Zohocorp ManageEngine Password Manager Pro: before 13.2 (fixed in 13.2); version 13.2 only
Published 2026-01-13. Last modified 2026-06-17.