Critical SSO Vulnerability in ManageEngine Allows Account Takeover
ID: 615c8311-3b7f-596b-8fee-4f1a73f462b7
STIX ID: report--615c8311-3b7f-596b-8fee-4f1a73f462b7
Feed Name: ThreatCluster
Threat Score
Zoho ManageEngine disclosed CVE-2026-11374, a critical (CVSS 9.0) vulnerability in several products integrated with AD360 (including ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus) that permits prediction of SSO tokens and could lead to account takeover and sensitive data exposure; affected versions are enumerated, the issue was reported via Zoho's bug bounty program, and users are urged to update while no exploitation has been confirmed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
