CVE-2026-11840: Zohocorp ManageEngine PAM360

High severity, CVSS 8.8. EPSS: 3.1% chance of exploitation in the next 30 days.

Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions before 8552 are vulnerable to authenticated SQL injection.

Affected products

  • Zohocorp ManageEngine PAM360: before 8552 (fixed in 8552)
  • Zohocorp ManageEngine Password Manager Pro: before 13232 (fixed in 13232)

Published 2026-08-13. Last modified 2026-08-31.