CVE-2026-6516

Versionen von ZohoCorp ManageEngine ADAudit Plus vor 8606 sind anfällig für die unbefugte Fernausführung von Code aufgrund der verwundbar… (CVE-2026-6516)

criticalEPSS 4.9 %

Beschreibung

Versionen von ZohoCorp ManageEngine ADAudit Plus vor 8606 sind anfällig für die unbefugte Fernausführung von Code aufgrund der verwundbaren Agent-API.

Metriken

Severity
critical
kein öffentlicher PoC bekannt
10.0
Quelle: nvd-v3
91.5 %
Kritisch — CVE liegt im obersten Fünftel aller heute bewerteten CVEs (Rang ≥ 80 %).
4.9 %
Moderat — Modell schätzt 1-10 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-07-23 17:22 UTC
CWE-78

Weakness-Klassen (CWE)

  • CWE-78Base

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

    The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Modified2026-07-24 05:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-6516","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalI…{"id":"CVE-2026-6516","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalI…
  2. New CVE Received2026-07-23 18:17 UTC· 0fc0942c-577d-436f-ae8e-945763c79b02
    • Affected: ManageEngine ADAudit Plus
    • Description: Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.
    • CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
    • CWE: CWE-78

Quellen & Referenzen

Verknüpfte Empfehlungen

IDCVE-2026-6516