Zoho Patches Critical “9.1” Flaw in ADSelfService Plus
ID: 3146e1f2-fdae-57df-aea9-acb572e89e47
STIX ID: report--3146e1f2-fdae-57df-aea9-acb572e89e47
Feed Name: securityonline.info
Threat Score
ManageEngine ADSelfService Plus has a critical vulnerability (CVE-2025-11250, CVSS 9.1) affecting builds 6518 and earlier; the vendor released a patch in build 6519 on 2025-10-01 and urges immediate updates. The flaw—discovered via the Zoho BugBounty program—could allow unauthorized access or system compromise involving Active Directory credentials, though specific exploit details and evidence of active exploitation are not provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
