logo

Critical SSO Vulnerability in ManageEngine Allows Account Takeover

ID: 615c8311-3b7f-596b-8fee-4f1a73f462b7

STIX ID: report--615c8311-3b7f-596b-8fee-4f1a73f462b7

Feed Name: ThreatCluster

Threat Score
72/100

Date Published: 2026-06-25

Date Updated: 2026-06-25

...
...

Zoho ManageEngine disclosed CVE-2026-11374, a critical (CVSS 9.0) vulnerability in several products integrated with AD360 (including ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus) that permits prediction of SSO tokens and could lead to account takeover and sensitive data exposure; affected versions are enumerated, the issue was reported via Zoho's bug bounty program, and users are urged to update while no exploitation has been confirmed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.