Skip to content
Critical SSO Vulnerability in ManageEngine Allows Account Takeover

Critical SSO Vulnerability in ManageEngine Allows Account Takeover

First seen 25 Jun 2026, 12:39 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •June 26, 2026 at 12:35 UTC

Zoho Corp. ManageEngine has disclosed a critical vulnerability tracked as CVE-2026-11374, affecting several of its products when integrated with AD360. The flaw allows attackers to predict single sign-on (SSO) tokens, potentially leading to account takeover and exposure of sensitive user information. Affected products include ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, with specific vulnerable versions listed. The vulnerability has a CVSS score of 9.0, indicating a critical risk. As of now, there are no confirmed reports of exploitation in the wild. Users are advised to update to the latest versions to mitigate the risk. The vulnerability was reported through the Zoho bug bounty program. This follows previous disclosures of critical vulnerabilities in ManageEngine products last November.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 97d ago How this analysis works

Timeline

2026-06-23
CVE-2026-11374 published
Zoho Corp. disclosed a critical SSO vulnerability affecting multiple ManageEngine products.
Heise.De
2026-06-24
Security advisory issued
ManageEngine released a security advisory detailing the critical SSO vulnerability and affected versions.
Heise.De
2026-06-25
Cybersecurity news coverage
Cybersecuritynews reported on the vulnerability, emphasizing its potential impact on user identity and role exposure.
Cybersecuritynews

More articles in this cluster (3)

Following this threat?

Track ManageEngine and CVE-2026-11374 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed