Skip to content
Critical RCE Vulnerability in ManageEngine Applications Manager Exploited

Critical RCE Vulnerability in ManageEngine Applications Manager Exploited

First seen 27 Sep 2026, 09:52 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 28, 2026 at 09:33 UTC
  • •CVE-2020-14008 allows remote code execution in ManageEngine Applications Manager.
  • •New exploit improves reliability over previous methods, bypassing upload failures.
  • •Default admin credentials increase vulnerability risk for many deployments.

A new exploit for CVE-2020-14008 has been released, targeting ManageEngine Applications Manager versions up to 14720. This vulnerability allows remote code execution via an authenticated command-execution primitive, enabling attackers to run arbitrary commands as the system account. The exploit bypasses the original proof-of-concept's fragile upload chain, improving reliability in real-world scenarios. It leverages PowerShell to fetch a payload from an attacker-controlled HTTP server. The exploit is parameterized for flexibility in targeting and callback configurations. Default credentials are often left unchanged, increasing the risk of exploitation. The exploit is available publicly, and security professionals are urged to assess their systems for vulnerability. Current status indicates that exploitation is possible, but no active exploitation in the wild has been confirmed yet.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2020-09-04
CVE-2020-14008 published
CVE-2020-14008 was published, detailing a remote code execution vulnerability in ManageEngine Applications Manager.
Sploitus
2026-05-10
First public PoC released
The first public proof-of-concept for CVE-2020-14008 was released, demonstrating the exploit's potential.
Sploitus
2026-09-26
New exploit tool published
An improved exploit tool for CVE-2020-14008 was published, enhancing reliability and ease of use.
Sploitus
2026-09-27
Exploit tool update released
An updated version of the exploit tool was released, further refining the attack method and parameters.
Sploitus

More articles in this cluster (2)

Following this threat?

Track CVE-2020-14008 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed