Skip to content
September 18, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Vulnerability Report
  • ManageEngine Account Takeover Flaw CVE-2026-11374
  • Vulnerability Report

ManageEngine Account Takeover Flaw CVE-2026-11374

Do Son June 25, 2026 2 minutes read
0
ManageEngine account takeover diagram explaining CVE-2026-11374 SSO ticket prediction
Add Daily CyberSecurity as a preferred source on Google
At a glance
  • CVE: CVE-2026-11374
  • CVSS: 9.0 (Critical · CVSSv3)
  • Product: zohocorp manageengine_adselfservice_plus
  • Affected: < 6529, < 6321, < 4817, < 8703
  • Impact: Account Takeover via Predictable SSO Ticket Generation
  • Status: No confirmed exploitation yet
  • Patched in: 6529, 6321, 4817, 8703
  • EPSS: 2.0% (30-day)
  • Action: Update to 6529, 6321, 4817, 8703 now

Track every Zoho CVE the moment it's exploited.

Get free email alerts →

TL;DR

Zoho Corporation disclosed a critical ManageEngine account takeover flaw tracked as CVE-2026-11374. This CVSS 9.0 vulnerability affects multiple ManageEngine products integrated within AD360. Consequently, unauthenticated attackers can predict SSO tickets and compromise user accounts.

Why it matters

This vulnerability carries a severe 9.0 CVSS score. Moreover, attackers can gain complete control over user accounts without any prior authentication. Furthermore, the targeted products handle sensitive administrative and auditing functions. A successful attack exposes identity data and role information. This level of access grants intruders deep reach into an organization’s internal network. Currently, no public proof-of-concept exists. The vendor also has not confirmed active exploitation in the wild.

How the attack works

The issue stems from weak single sign-on ticket generation. When users sign in via SSO, the system generates tickets to authenticate the session. However, the system uses predictable patterns to create these tokens. An unauthenticated attacker can mathematically predict a valid SSO ticket. According to the advisory, this flaw allows attackers to “obtain the targeted user’s identity and role information.” Ultimately, predicting the ticket results in a total account takeover.

Affected versions

Specifically, the security flaw affects four ManageEngine tools when deployed as integrated components within ManageEngine AD360.

  • ADSelfService Plus: Builds 6528 and earlier.
  • Recovery Manager Plus: Builds 6320 and earlier.
  • M365 Manager Plus: Builds 4816 and earlier.
  • ADAudit Plus: Builds 8702 and earlier.

Patch or mitigation steps

Therefore, administrators must apply the latest service packs immediately. Zoho resolved the issue by strengthening how the system generates SSO tickets. This fix ensures the tickets “can no longer be predicted by an unauthenticated attacker.” You can download the required service packs directly from the ManageEngine official security advisory. First, patch ADSelfService Plus to build 6529. Next, update Recovery Manager Plus to 6321. Then, upgrade M365 Manager Plus to 4817. Finally, secure ADAudit Plus by installing build 8703.

Related coverage

  • CVE-2025-62593: Ray RCE Exploited in the Wild, PoC Public
  • HP Fixes Critical HPLIP Vulnerabilities
  • Urgent Chrome Update: Google Patches Critical Zero-Day (CVE-2025-6558) Under Active Attack
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Stay Ahead of the Threat

Join security professionals receiving zero-hour CVE alerts, PoC updates, and threat analysis directly to their inbox.

No spam. One actionable email per week. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: Account Takeover AD360 CVE-2026-11374 ManageEngine SSO Vulnerability

Leave a Reply Cancel reply

You must be logged in to post a comment.

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2026-76460CVSS 10.0
    A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to...
    Admin intelCISA KEV📅 Added to KEV: Sep 16, 2026📅 Updated: Sep 16, 2026
  • CVE-2026-89026CVSS 9.8
    The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT...
    Admin intel📅 Updated: Sep 16, 2026
  • CVE-2026-58704
    In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This...
    Admin intelCISA KEV📅 Added to KEV: Sep 16, 2026📅 Updated: Sep 16, 2026
  • CVE-2026-87886
    Exploitation of this vulnerability has been detected in the wild in limited, targeted attacks against Acronis Backup plugin...
    Admin intelCISA KEV📅 Added to KEV: Sep 16, 2026📅 Updated: Sep 16, 2026
  • CVE-2026-87827CVSS 10.0
    Certain KGUARD DVR devices running vulnerable firmware expose a system command execution service on all network interfaces without...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-78006CVSS 9.8
    The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to,...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-39364
    Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-27540CVSS 9.0
    Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture...
    Admin intel📅 Updated: Sep 15, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-20325CVSS 9.9
    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has...
    📅 Updated: Sep 18, 2026
  • CVE-2026-69843CVSS 10.0
    No description available
    📅 Updated: Sep 18, 2026
  • CVE-2026-85878CVSS 9.9
    No description available
    📅 Updated: Sep 18, 2026
  • CVE-2026-70009CVSS 9.3
    No description available
    📅 Updated: Sep 18, 2026
  • CVE-2026-70200CVSS 10.0
    No description available
    📅 Updated: Sep 18, 2026
  • CVE-2026-85885CVSS 9.9
    No description available
    📅 Updated: Sep 18, 2026
  • CVE-2026-85889CVSS 10.0
    No description available
    📅 Updated: Sep 18, 2026
  • CVE-2026-87701CVSS 9.6
    No description available
    📅 Updated: Sep 18, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.