FAIL › dossier
ManageEngine
PRODUCT· dossier confidence 20%
ManageEngine is a provider of IT operations and security management software with a documented history of critical and high-severity remote code execution vulnerabilities. Its security posture is compromised by a pattern of relying on unpatched third-party dependencies and failing to address authentication bypasses that directly enable remote code execution.
PROFILE
CategoryIT Operations Management & SecurityWhat they doManageEngine provides IT operations management, identity and access management, and unified service management solutions for enterprises.
Websitehttps://www.manageengine.com ↗
SECURITY POSTURE
ManageEngine has a poor security track record characterized by multiple critical and high-severity remote code execution (RCE) vulnerabilities across its product line, often stemming from unpatched dependencies or authentication bypasses.
Notable failures
- CVE-2021-40539: Critical RCE via authentication bypass in ADSelfService Plus REST API
- CVE-2022-47966: Critical RCE due to unpatched Apache Santuario dependency
- CVE-2022-28810: High RCE in ADSelfService Plus during password reset operations
Patterns: repeated unpatched RCE vulnerabilities across multiple products; vulnerabilities exploited via outdated third-party dependencies; authentication bypasses leading to remote code execution
FAILURE HISTORY · 6
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2021-11-03 | CVE-2021-40539 | critical | Zoho's ManageEngine ADSelfService Plus exposed via unpatched RCE flaw exploited in the wild |
| 2023-01-23 | CVE-2022-47966 | critical | Zoho ManageEngine products suffered an unauthenticated remote code execution vulnerability due to an outdated third-party dependency, Apache Santuario. |
| 2021-11-03 | CVE-2020-10189 | high | Unauthenticated remote code execution via file upload in Zoho ManageEngine Desktop Central. |
| 2023-03-07 | CVE-2022-28810 | high | Zoho's ManageEngine ADSelfService Plus exposed RCE due to unpatched vulnerability during password change/reset, exploited in the wild. |
| 2022-09-22 | CVE-2022-35405 | high | Zoho ManageEngine PAM360, Password Manager Pro, and Access Manager Plus allow remote code execution due to unpatched vulnerabilities. |
| 2021-11-03 | CVE-2019-8394 | high | Remote attackers exploited an unspecified file upload vulnerability in Zoho ManageEngine ServiceDesk Plus to upload files via the login page customization feature. |
DOSSIER SOURCES
- ManageEngine Blog · www.manageengine.com
- Threats and Patches | ManageEngine Endpoint Central · www.manageengine.com
- ManageEngine Status. Check if ManageEngine is down or ... - StatusGator · statusgator.com
- ManageEngine - Overview, News & Similar companies | ZoomInfo.com · www.zoominfo.com
- ManageEngine Blog · www.manageengine.com
- Denmark - Wikipedia · en.wikipedia.org
Open questions: Exact founding year and headquarters location require external verification beyond the provided web evidence. · Current size and ownership structure are not explicitly stated in the provided web evidence.
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-18 04:07:49.842869+00:00