logo

ADAudit Plus Flaw CVE-2026-6516 Allows Unauthenticated Remote Code Execution at CVSS 10

ID: 5d80a4d7-c49d-5660-88fe-b0bd3dcf4e56

STIX ID: report--5d80a4d7-c49d-5660-88fe-b0bd3dcf4e56

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-07-24

Date Updated: 2026-07-25

Author: Do Son

...
...

ManageEngine patched a critical ADAudit Plus vulnerability (CVE-2026-6516) — two Agent API flaws (authentication bypass and path traversal) that can be chained to enable unauthenticated remote code execution (CVSS 10.0). The vendor fixed the issue in build 8606 (17 April 2026); no active exploitation has been reported, and administrators are advised to apply the update and upgrade agents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.