CVE-2026-6516: Zohocorp ManageEngine Adaudit Plus

Critical severity, CVSS 10.0. EPSS: 4.7% chance of exploitation in the next 30 days.

Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.

Affected products

  • Zohocorp ManageEngine Adaudit Plus: before 8606 (fixed in 8606)

Published 2026-07-23. Last modified 2026-07-24.