CVE-2026-14828: Zohocorp ManageEngine Access Manager Plus
High severity, CVSS 8.8. EPSS: 1.4% chance of exploitation in the next 30 days.
Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerability.
Affected products
- Zohocorp ManageEngine Access Manager Plus: before 4405 (fixed in 4405)
- Zohocorp ManageEngine PAM360: before 8561 (fixed in 8561)
- Zohocorp ManageEngine Password Manager Pro: before 13235 (fixed in 13235)
Published 2026-09-02. Last modified 2026-09-08.