CVE-2025-5494: Zohocorp ManageEngine Endpoint Central
High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.
ZohoCorp ManageEngine Endpoint Central was impacted by an improper privilege management issue in the agent setup. This issue affects Endpoint Central: through 11.4.2500.25, through 11.4.2508.13.
Affected products
- Zohocorp ManageEngine Endpoint Central: before 11.4.2500.26 (fixed in 11.4.2500.26); from 11.4.2508.01, before 11.4.2508.14 (fixed in 11.4.2508.14)
Published 2025-09-25. Last modified 2026-06-17.