CVE-2026-11374: Zohocorp ManageEngine Adaudit Plus

Critical severity, CVSS 9.0. EPSS: 2.5% chance of exploitation in the next 30 days.

In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by an unauthenticated user, leading to account takeover.

Affected products

  • Zohocorp ManageEngine Adaudit Plus: before 8703 (fixed in 8703)
  • Zohocorp ManageEngine Adselfservice Plus: before 6529 (fixed in 6529)
  • Zohocorp ManageEngine m365 Manager Plus: before 4817 (fixed in 4817)
  • Zohocorp ManageEngine Recovery Manager Plus: before 6321 (fixed in 6321)

Published 2026-06-23. Last modified 2026-06-24.