Skip to content
COOEY

FAIL › dossier

ManageEngine

PRODUCT

· dossier confidence 20%

ManageEngine is a provider of IT operations and security management software with a documented history of critical and high-severity remote code execution vulnerabilities. Its security posture is compromised by a pattern of relying on unpatched third-party dependencies and failing to address authentication bypasses that directly enable remote code execution.

PROFILE
CategoryIT Operations Management & SecurityWhat they doManageEngine provides IT operations management, identity and access management, and unified service management solutions for enterprises. Websitehttps://www.manageengine.com ↗
SECURITY POSTURE

ManageEngine has a poor security track record characterized by multiple critical and high-severity remote code execution (RCE) vulnerabilities across its product line, often stemming from unpatched dependencies or authentication bypasses.

Notable failures
  • CVE-2021-40539: Critical RCE via authentication bypass in ADSelfService Plus REST API
  • CVE-2022-47966: Critical RCE due to unpatched Apache Santuario dependency
  • CVE-2022-28810: High RCE in ADSelfService Plus during password reset operations
Patterns: repeated unpatched RCE vulnerabilities across multiple products; vulnerabilities exploited via outdated third-party dependencies; authentication bypasses leading to remote code execution
FAILURE HISTORY · 6
DATEEVENTSEVSUMMARY
2021-11-03 CVE-2021-40539 critical Zoho's ManageEngine ADSelfService Plus exposed via unpatched RCE flaw exploited in the wild
2023-01-23 CVE-2022-47966 critical Zoho ManageEngine products suffered an unauthenticated remote code execution vulnerability due to an outdated third-party dependency, Apache Santuario.
2021-11-03 CVE-2020-10189 high Unauthenticated remote code execution via file upload in Zoho ManageEngine Desktop Central.
2023-03-07 CVE-2022-28810 high Zoho's ManageEngine ADSelfService Plus exposed RCE due to unpatched vulnerability during password change/reset, exploited in the wild.
2022-09-22 CVE-2022-35405 high Zoho ManageEngine PAM360, Password Manager Pro, and Access Manager Plus allow remote code execution due to unpatched vulnerabilities.
2021-11-03 CVE-2019-8394 high Remote attackers exploited an unspecified file upload vulnerability in Zoho ManageEngine ServiceDesk Plus to upload files via the login page customization feature.
Open questions: Exact founding year and headquarters location require external verification beyond the provided web evidence. · Current size and ownership structure are not explicitly stated in the provided web evidence.
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-18 04:07:49.842869+00:00