ManageEngine AD360 Integration Flaw Exposes User Identity and Role Information to Attackers
ID: 5db76bbf-5fa5-579e-87e2-22cff783f633
STIX ID: report--5db76bbf-5fa5-579e-87e2-22cff783f633
Feed Name: cybersecurityNews.com
Threat Score
ManageEngine disclosed CVE-2026-11374, a high-severity flaw in AD360-integrated identity products (ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, ADAudit Plus) where predictable SSO tokens allow unauthenticated attackers to impersonate users and access sensitive identity and audit data; patches were released in early June 2026 and organizations are advised to apply updates and monitor authentication activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
