TL;DR
ManageEngine patched a critical ADAudit Plus vulnerability tracked as CVE-2026-6516. Two weaknesses in the product’s Agent APIs, an authentication bypass and a path traversal, chain into unauthenticated remote code execution. Build 8606 carries the fix, released on 17 April 2026.
- CVE: CVE-2026-6516
- CVSS: 10.0 (Critical · CVSSv3)
- Product: Zohocorp ManageEngine ADAudit Plus
- Affected: < 8606
- Impact: Remote Code Execution
- Status: No confirmed exploitation yet
- Patched in: 8606
- Action: Update to 8606 now
Why it matters
ADAudit Plus watches Active Directory for a living. It runs agents on domain controllers, file servers, and workstations. Compromising the audit server therefore places an attacker right beside the directory it monitors.
Zoho’s ManageEngine rates the issue Critical. The advisory heading assigns a CVSS score of 10, the maximum the scale allows.
How the attack works
The advisory names two separate weaknesses in the Agent APIs. One permits authentication bypass. The other permits path traversal. ManageEngine publishes no further technical detail on either.
Chained together, they remove the need for valid credentials. The vendor states the outcome plainly: “An unauthenticated adversary could combine these vulnerabilities to potentially achieve remote code execution.”
Exploitation status
ManageEngine reports no exploitation in the wild. No public proof-of-concept has appeared either. A researcher credited as Linhlt of VCB reported the flaw.
Affected versions and patching
Every ADAudit Plus build below 8606 is affected. This ADAudit Plus vulnerability was fixed back in April, so the real question is whether your instance ever took the update.
Three steps close the gap:
- Apply the service pack to reach build 8606
- Upgrade Windows agents running anything older than 7060
- Upgrade every Mac agent, whatever version it currently runs
Check agent versions in the web console under Configuration, then Agent Management, then Manage. Step-by-step upgrade instructions sit in ManageEngine’s advisory for CVE-2026-6516.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.