CVE-2026-75791: Zohocorp ManageEngine Adselfservice Plus

High severity, CVSS 8.6. EPSS: 1.7% chance of exploitation in the next 30 days.

Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to an authentication bypass vulnerability in the REST API.

Affected products

  • Zohocorp ManageEngine Adselfservice Plus: before 7001 (fixed in 7001)

Published 2026-09-22. Last modified 2026-09-22.