CVE-2026-6516
Zoho ManageEngine ADAudit Plus vulnerability analysis and mitigation

Overview

CVE-2026-6516 is a critical unauthenticated remote code execution (RCE) vulnerability in Zohocorp ManageEngine ADAudit Plus affecting all builds prior to version 8606. The vulnerability stems from flaws in the product's agent API, specifically involving authentication bypass and path traversal weaknesses that can be chained to achieve RCE. It was disclosed on July 23, 2026, with a fix released in build 8606 (fixed on April 17, 2026). The vulnerability carries a CVSS v3.1 base score of 10.0 (Critical) (ManageEngine Advisory, GitHub Advisory).

Technical details

The root cause is classified as CWE-78 (Improper Neutralization of Special Elements used in an OS Command / OS Command Injection), arising from vulnerabilities in the ADAudit Plus agent APIs that permit authentication bypass and path traversal (GitHub Advisory, ManageEngine Advisory). An unauthenticated remote attacker can exploit these weaknesses over the network with low attack complexity and no user interaction required. The attack vector is network-accessible, requires no privileges, and results in a scope change — meaning the impact extends beyond the vulnerable component itself. The vulnerability was reported by researcher Linhlt of VCB (ManageEngine Advisory).

Impact

Successful exploitation allows an unauthenticated remote attacker to execute arbitrary OS commands on the affected ADAudit Plus server, potentially achieving complete system compromise. Given that ADAudit Plus is an Active Directory auditing solution with privileged access to AD environments, exploitation could expose highly sensitive audit logs, credentials, and AD configuration data, and could facilitate lateral movement across the enterprise network. The CVSS scoring reflects high confidentiality and integrity impact with a changed scope, underscoring the risk of cross-component compromise (ManageEngine Advisory, GitHub Advisory).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Feedly). The vulnerability is rated automatable by NVD SSVC analysis, meaning exploitation can be scripted without manual interaction. The EPSS score is approximately 4.73% (91st percentile), indicating a relatively elevated probability of exploitation within 30 days compared to most CVEs. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection plugins are available via Nessus (plugin 331343) and Qualys (detection ID 520227) (Feedly).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible ManageEngine ADAudit Plus instances running builds prior to 8606 using tools such as Shodan, Censys, or FOFA, targeting default ports used by the ADAudit Plus web console and agent API.
  2. Identify vulnerable agent API endpoint: Locate the agent API endpoints exposed by ADAudit Plus, which are accessible without authentication due to the authentication bypass flaw.
  3. Exploit authentication bypass: Send a crafted unauthenticated HTTP request to the vulnerable agent API endpoint, leveraging the authentication bypass weakness to gain access to privileged API functionality.
  4. Leverage path traversal: Use the path traversal vulnerability in conjunction with the authentication bypass to access restricted resources or functionality within the application.
  5. Inject OS command payload: Submit a malicious request containing OS command injection payloads (CWE-78) through the vulnerable agent API parameter, causing the server to execute arbitrary system commands as the ADAudit Plus service account.
  6. Achieve remote code execution: The injected commands execute on the server, enabling the attacker to establish a reverse shell, exfiltrate AD audit data, deploy malware, or pivot to other systems in the Active Directory environment (ManageEngine Advisory, GitHub Advisory).

Indicators of compromise

  • Network: Unexpected or anomalous HTTP/HTTPS requests to ADAudit Plus agent API endpoints from external or untrusted IP addresses; outbound connections from the ADAudit Plus server to unknown external hosts (potential reverse shell or C2 activity); FOFA/Shodan scanning activity targeting ADAudit Plus default ports.
  • Logs: ADAudit Plus web server access logs showing unauthenticated requests to agent API endpoints with unusual parameters or path traversal sequences (e.g., ../, %2e%2e%2f); OS-level command execution logs showing processes spawned by the ADAudit Plus service account that are inconsistent with normal operations.
  • File System: Unexpected files (web shells, scripts, executables) written to the ADAudit Plus installation directory or temp directories; new scheduled tasks or services created by the ADAudit Plus service account.
  • Process: Unusual child processes spawned by the ADAudit Plus Java process (e.g., cmd.exe, powershell.exe, bash, curl, wget, net.exe); unexpected network connections initiated by the ADAudit Plus process.

Mitigation and workarounds

The primary remediation is to update ManageEngine ADAudit Plus to build 8606 or later using the official service pack (ManageEngine Advisory). After updating, administrators should also upgrade Windows agents to version 7060 or later via the ADAudit Plus web console under Configuration → Agent Management → Manage → Installed Version. Mac agents should be upgraded to the latest version regardless of current version. If immediate patching is not feasible, restrict network access to the ADAudit Plus agent API endpoints to trusted internal networks only, implement network segmentation, and monitor for suspicious activity on affected systems.

Community reactions

The vulnerability received coverage from security news outlets including SecurityOnline.info and SystemTek shortly after disclosure (SecurityOnline, SystemTek). The Western Australian Government SOC issued an advisory on July 24, 2026, urging organizations to patch promptly (WA SOC Advisory). Horizon3.ai published attack research on the vulnerability, and threat intelligence platforms including ThreadLinqs and CTIP Pilot flagged it as a notable risk. Social media activity on platforms such as Mastodon and LinkedIn noted the critical severity and the absence of a public PoC at the time of disclosure.

Additional resources


SourceThis report was generated using AI

Related Zoho ManageEngine ADAudit Plus vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-6516CRITICAL10
  • Zoho ManageEngine ADAudit Plus logoZoho ManageEngine ADAudit Plus
  • cpe:2.3:a:zohocorp:manageengine_adaudit_plus
NoYesJul 23, 2026
CVE-2026-11374CRITICAL9
  • Zoho ManageEngine ADSelfService Plus logoZoho ManageEngine ADSelfService Plus
  • cpe:2.3:a:zohocorp:manageengine_adaudit_plus
NoYesJun 23, 2026
CVE-2025-41444HIGH8.3
  • Zoho ManageEngine ADAudit Plus logoZoho ManageEngine ADAudit Plus
  • cpe:2.3:a:zohocorp:manageengine_adaudit_plus
NoYesJun 09, 2025
CVE-2025-36528HIGH8.3
  • Zoho ManageEngine ADAudit Plus logoZoho ManageEngine ADAudit Plus
  • cpe:2.3:a:zohocorp:manageengine_adaudit_plus
NoYesJun 09, 2025
CVE-2025-27709HIGH8.3
  • Zoho ManageEngine ADAudit Plus logoZoho ManageEngine ADAudit Plus
  • cpe:2.3:a:zohocorp:manageengine_adaudit_plus
NoYesJun 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management