Manageengine Applications Manager
63 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Manageengine Applications Manager, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
Manageengine Applications Manager CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 1 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 1 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 1 |
| 2025-11 | 1 |
| 2025-12 | 1 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 6 |
Severity
How the 63 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical20
- High25
- Medium18
Latest CVEs
The 15 most recently published vulnerabilities affecting Manageengine Applications Manager.
- CVE-2026-86678Broken Authentication vulnerability8.8
- CVE-2026-86677Broken Authentication vulnerability8.8
- CVE-2026-86679Broken Access Control vulnerability7.1
- CVE-2026-86683Broken Authentication Vulnerability8.1
- CVE-2026-86681Broken Access Control vulnerability7.6
- CVE-2026-86708Sensitive data exposure10.0
- CVE-2025-9787Stored XSS6.1
- CVE-2025-9223Command Injection8.8
- CVE-2025-6239Information disclosure6.5
- CVE-2025-27930Stored XSS6.4
- CVE-2024-41140Improper Authorization8.1
- CVE-2024-5678SQL Injection4.7
- CVE-2023-38333Zoho ManageEngine Applications Manager through 16530 allows reflected XSS while logged in.6.1
- CVE-2023-29442Zoho ManageEngine Applications Manager before 16400 allows proxy.html DOM XSS.6.1
- CVE-2023-28341Stored Cross site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager through 16340 allows an unauthenticated user to inject malicious javascript on the incorrect login details ...6.1
Product grouping is registry-driven, with AI assist and human review. How it works