CVE-2026-3183: Zohocorp ManageEngine Adselfservice Plus

High severity, CVSS 7.1. EPSS: 1.2% chance of exploitation in the next 30 days.

Zohocorp ManageEngine ADSelfService Plus versions before 6524 are vulnerable to Multi Factor Authentication Bypass.

Affected products

  • Zohocorp ManageEngine Adselfservice Plus: before 6524 (fixed in 6524)

Published 2026-07-21. Last modified 2026-07-21.