ManageEngine AD360 Integrated Products Hit by Account Takeover Vulnerability
ID: 3591f886-de69-5fdb-8179-a811c8b86dad
STIX ID: report--3591f886-de69-5fdb-8179-a811c8b86dad
Feed Name: GBHackers
ManageEngine disclosed CVE-2026-11374, a critical account-takeover vulnerability in AD360's SSO ticket generation that impacts ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus and ADAudit Plus when integrated with AD360; predictable SSO tokens can allow unauthenticated impersonation and privilege escalation. Fixed builds (ADSelfService Plus 6529, RecoveryManager Plus 6321, M365 Manager Plus 4817, ADAudit Plus 8703) were released in June 2026 and organizations are urged to apply updates and review authentication logs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
