CVE-2025-5494: Zohocorp ManageEngine Endpoint Central

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

ZohoCorp ManageEngine Endpoint Central was impacted by an improper privilege management issue in the agent setup. This issue affects Endpoint Central: through 11.4.2500.25, through 11.4.2508.13.

Affected products

  • Zohocorp ManageEngine Endpoint Central: before 11.4.2500.26 (fixed in 11.4.2500.26); from 11.4.2508.01, before 11.4.2508.14 (fixed in 11.4.2508.14)

Published 2025-09-25. Last modified 2026-06-17.