logo

Zoho Patches Critical “9.1” Flaw in ADSelfService Plus

ID: 3146e1f2-fdae-57df-aea9-acb572e89e47

STIX ID: report--3146e1f2-fdae-57df-aea9-acb572e89e47

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-01-15

Date Updated: 2026-04-23

Author: Ddos

...
...

ManageEngine ADSelfService Plus has a critical vulnerability (CVE-2025-11250, CVSS 9.1) affecting builds 6518 and earlier; the vendor released a patch in build 6519 on 2025-10-01 and urges immediate updates. The flaw—discovered via the Zoho BugBounty program—could allow unauthorized access or system compromise involving Active Directory credentials, though specific exploit details and evidence of active exploitation are not provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.