Zohocorp has 8 CVEs on record between 2020 and 2026. Disclosure cadence is accelerating: 5 in the last 90 days against 1 in the 90 before. The busiest recent month was September 2026 with 5. The median CVSS is 7.4 (high), with 2 rated critical. 13% have been exploited in the wild — well above the 1% corpus average, so Zohocorp flaws are worth patching on sight. The most common weakness class is CWE-269 (3). Most affected products: ManageEngine Endpoint Central (3), ManageEngine DataSecurity Plus (2), manageengine_access_manager_plus (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 13% vs 1% corpus
- Median CVSS
- 7.4
- Publish → KEV
- —(1)
- Last 90 days
- 5 prev 1
Products
- ManageEngine Endpoint Central 3
- ManageEngine DataSecurity Plus 2
- manageengine_access_manager_plus 1
- manageengine_adselfservice_plus 1
- manageengine_exchange_reporter_plus 1
Worst active — by depth score
CVE-2022-47966Critical· 9.8Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in t…100CVE-2018-5353Critical· 9.8The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing68CVE-2026-18912High· 7.7ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allowing an authenticated technician to execute arbitrary SQL queries through the Reports module.43CVE-2026-18911High· 7.5ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolled agents to send requests without proper authentication.41CVE-2026-27655High· 7.3Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions Based on Mailboxes report.40
Zohocorp vulnerabilities
CVEs affecting Zohocorp, newest first. Open any entry for full detail, references, and exploit status.
8 CVEsRSS
CVE-2026-18912High· 7.7ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allowing an authenticated technician to execute arbitrary SQL queries through the Reports module.
ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allowing an authenticated technician to execute arbitrary SQL queries through the Reports module.
CVE-2026-18911High· 7.5ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolled agents to send requests without proper authentication.
ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolled agents to send requests without proper authentication.
CVE-2026-77697Medium· 6.3Zohocorp ManageEngine Endpoint Central versions below 11.4.2540.23 are vulnerable to Privilege Escalation During JAR Extraction
Zohocorp ManageEngine Endpoint Central versions below 11.4.2540.23 are vulnerable to Privilege Escalation During JAR Extraction
CVE-2026-77699Medium· 5.0Zohocorp ManageEngine Endpoint Central versions below 11.5.2605.01 are vulnerable to Local privilege escalation due to loading a dll from an untrusted path.
Zohocorp ManageEngine Endpoint Central versions below 11.5.2605.01 are vulnerable to Local privilege escalation due to loading a dll from an untrusted path.
CVE-2026-77698Medium· 5.7Zohocorp ManageEngine Endpoint Central versions before 11.5.2605.01 are vulnerable to local privilege escalation due to Agent upgrade.
Zohocorp ManageEngine Endpoint Central versions before 11.5.2605.01 are vulnerable to local privilege escalation due to Agent upgrade.
CVE-2026-27655High· 7.3Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions Based on Mailboxes report.
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions Based on Mailboxes report.
CVE-2022-47966Critical· 9.8CISA KEVPoCMultiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in t…
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in t…
CVE-2018-5353Critical· 9.8PoCThe custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing
The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. It does not authenticate the intended server before opening a browser w…