NewsSecurity Vulnerabilities

Zohocorp Unauthenticated Remote Code Execution Vulnerability (CVE-2026-6516) 

CVE number = CVE-2026-6516

Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.

An unauthenticated adversary could combine these vulnerabilities to potentially achieve remote code execution.

  1. Update your ADAudit Plus instance to the latest version — 8606 — using the service pack.
  2. If your Windows agent version is earlier than 7060, upgrade the agent by following the steps on this page.
    • To check the agent version, open the ADAudit Plus web console and navigate to: Configuration → Agent Management → Manage → Installed Version column.
  3. If you have Mac agents installed, upgrade them to the latest version by following the steps on this page, regardless of the current version.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.