EXPOSURES › CVE-2022-47966
CVE-2022-47966
CRITICAL ⌖ ON CISA KEV · EXPLOITEDZoho ManageEngine products suffered an unauthenticated remote code execution vulnerability due to an outdated third-party dependency, Apache Santuario.
An unauthenticated remote code execution flaw in multiple Zoho ManageEngine products stemmed from an outdated Apache Santuario dependency, allowing attackers to execute arbitrary code without authentication. This failure is critical for DIB organizations because it directly enables ransomware attacks and violates CMMC/NIST 800-171 requirements for patch management and supply-chain risk control. Organizations must immediately patch these products and audit their third-party dependency management processes to prevent similar exposures.
Shame score — The vulnerability was actively exploited in the wild and linked to ransomware, demonstrating severe negligence in patching a known, unauthenticated RCE flaw.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Multiple Zoho ManageEngine products contain an unauthenticated remote code execution vulnerability due to the usage of an outdated third-party dependency, Apache Santuario.