CVE Tools

ManageEngine Account Takeover Flaw CVE-2026-11374

Daily CyberSecurity (securityonline.info)

PatchADSelfService PlusRecovery Manager Plus

Our summary

Zoho disclosed a critical account takeover weakness, CVE-2026-11374 (CVSS 9.0), in zohocorp manageengine_adselfservice_plus when deployed as part of ManageEngine AD360. The flaw allows unauthenticated attackers to predict SSO tickets, letting them obtain user identity/role information and take over targeted accounts. Organizations using affected builds—6528 or earlier, 6320 or earlier, 4816 or earlier, and 8702 or earlier—should upgrade to 6529, 6321, 4817, and 8703 immediately, as exploitation has not been confirmed in the wild.

Read at Daily CyberSecurity (securityonline.info)

Daily CyberSecurity (securityonline.info) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store