CVE-2025-9428: Zohocorp ManageEngine Analytics Plus

High severity, CVSS 8.8. EPSS: 27.4% chance of exploitation in the next 30 days.

Zohocorp ManageEngine Analytics Plus versions 6171 and prior are vulnerable to authenticated SQL Injection via the key update api.

Affected products

  • Zohocorp ManageEngine Analytics Plus: before 6.1 (fixed in 6.1); version 6.1 only

Published 2025-10-21. Last modified 2026-10-08.