VulnSea

Zohocorp has 8 CVEs on record between 2020 and 2026. Disclosure cadence is accelerating: 5 in the last 90 days against 1 in the 90 before. The busiest recent month was September 2026 with 5. The median CVSS is 7.4 (high), with 2 rated critical. 13% have been exploited in the wild — well above the 1% corpus average, so Zohocorp flaws are worth patching on sight. The most common weakness class is CWE-269 (3). Most affected products: ManageEngine Endpoint Central (3), ManageEngine DataSecurity Plus (2), manageengine_access_manager_plus (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
13% vs 1% corpus
Median CVSS
7.4
Publish → KEV
(1)
Last 90 days
5 prev 1

Products

  • ManageEngine Endpoint Central 3
  • ManageEngine DataSecurity Plus 2
  • manageengine_access_manager_plus 1
  • manageengine_adselfservice_plus 1
  • manageengine_exchange_reporter_plus 1
8
Total CVEs
2
Critical
1
CISA KEV
1
Exploited

Zohocorp vulnerabilities

CVEs affecting Zohocorp, newest first. Open any entry for full detail, references, and exploit status.

8 CVEsRSS

CVE-2026-18912High· 7.7
4d ago

ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allowing an authenticated technician to execute arbitrary SQL queries through the Reports module.

ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allowing an authenticated technician to execute arbitrary SQL queries through the Reports module.

TwilightZohocorp · ManageEngine DataSecurity PlusEPSS 1.5%via NVD
CVE-2026-18911High· 7.5
4d ago

ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolled agents to send requests without proper authentication.

ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolled agents to send requests without proper authentication.

TwilightZohocorp · ManageEngine DataSecurity PlusEPSS 1.1%via NVD
CVE-2026-77697Medium· 6.3
2w ago

Zohocorp ManageEngine Endpoint Central versions below 11.4.2540.23 are vulnerable to Privilege Escalation During JAR Extraction

Zohocorp ManageEngine Endpoint Central versions below 11.4.2540.23 are vulnerable to Privilege Escalation During JAR Extraction

SunlitZohocorp · ManageEngine Endpoint CentralEPSS 0.25%via NVD
CVE-2026-77699Medium· 5.0
2w ago

Zohocorp ManageEngine Endpoint Central versions below 11.5.2605.01 are vulnerable to Local privilege escalation due to loading a dll from an untrusted path.

Zohocorp ManageEngine Endpoint Central versions below 11.5.2605.01 are vulnerable to Local privilege escalation due to loading a dll from an untrusted path.

SunlitZohocorp · ManageEngine Endpoint CentralEPSS 0.16%via NVD
CVE-2026-77698Medium· 5.7
2w ago

Zohocorp ManageEngine Endpoint Central versions before 11.5.2605.01 are vulnerable to local privilege escalation due to Agent upgrade.

Zohocorp ManageEngine Endpoint Central versions before 11.5.2605.01 are vulnerable to local privilege escalation due to Agent upgrade.

SunlitZohocorp · ManageEngine Endpoint CentralEPSS 0.22%via NVD
CVE-2026-27655High· 7.3
5mo ago

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions Based on Mailboxes report.

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions Based on Mailboxes report.

Twilightzohocorp · manageengine_exchange_reporter_plusEPSS 0.53%via NVD
CVE-2022-47966Critical· 9.8CISA KEVPoC
3y ago

Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in t…

Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in t…

Hadalzohocorp · manageengine_access_manager_plusEPSS 100%via NVD
CVE-2018-5353Critical· 9.8PoC
5y ago

The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing

The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. It does not authenticate the intended server before opening a browser w…

Abyssalzohocorp · manageengine_adselfservice_plusEPSS 11%via NVD
Zohocorp vulnerabilities (CVEs) · VulnSea