logo

ManageEngine AD360 Integrated Products Hit by Account Takeover Vulnerability

ID: 3591f886-de69-5fdb-8179-a811c8b86dad

STIX ID: report--3591f886-de69-5fdb-8179-a811c8b86dad

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-06-25

Date Updated: 2026-06-25

Author: Divya

...
...

ManageEngine disclosed CVE-2026-11374, a critical account-takeover vulnerability in AD360's SSO ticket generation that impacts ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus and ADAudit Plus when integrated with AD360; predictable SSO tokens can allow unauthenticated impersonation and privilege escalation. Fixed builds (ADSelfService Plus 6529, RecoveryManager Plus 6321, M365 Manager Plus 4817, ADAudit Plus 8703) were released in June 2026 and organizations are urged to apply updates and review authentication logs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.