Zohocorp Unauthenticated Remote Code Execution Vulnerability (CVE-2026-6516)
CVE number = CVE-2026-6516
Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.
An unauthenticated adversary could combine these vulnerabilities to potentially achieve remote code execution.
- Update your ADAudit Plus instance to the latest version — 8606 — using the service pack.
- If your Windows agent version is earlier than 7060, upgrade the agent by following the steps on this page.
- To check the agent version, open the ADAudit Plus web console and navigate to: Configuration → Agent Management → Manage → Installed Version column.
- If you have Mac agents installed, upgrade them to the latest version by following the steps on this page, regardless of the current version.

I am one of the editors here at www.systemtek.co.uk I am a UK based technology professional, with an interest in computer security and telecoms.
