CVE-2026-5785: Zohocorp ManageEngine PAM360

High severity, CVSS 8.1. EPSS: 2.6% chance of exploitation in the next 30 days.

Zohocorp ManageEngine PAM360 versions before 8531 and ManageEngine Password Manager Pro versions from 8600 to 13230 are vulnerable to Authenticated SQL injection in the query report module.

Affected products

  • Zohocorp ManageEngine PAM360: before 8531 (fixed in 8531)
  • Zohocorp ManageEngine Password Manager Pro: from 8600, up to and including 13230

Published 2026-04-16. Last modified 2026-06-17.