Skip to content
COOEY

FAIL › dossier

Zoho

VENDOR

· dossier confidence 20%

Zoho ManageEngine is a vendor of IT management and endpoint security software with a documented history of critical and high-severity remote code execution vulnerabilities. Their security posture is compromised by a pattern of unpatched dependencies and authentication bypasses that allow attackers to execute arbitrary code across their product portfolio.

PROFILE
CategoryIT Management & Endpoint SecurityWhat they doZoho ManageEngine provides IT management, endpoint security, and identity management software solutions for enterprises. Websitehttps://www.manageengine.com ↗
SECURITY POSTURE

The company has a poor security track record characterized by a high frequency of critical and high-severity remote code execution (RCE) vulnerabilities across its ManageEngine product line, often stemming from unpatched dependencies, authentication bypasses, and file upload flaws.

Notable failures
  • CVE-2021-40539: Critical RCE via authentication bypass in ADSelfService Plus
  • CVE-2022-47966: Critical RCE via outdated Apache Santuario dependency
  • CVE-2021-44515: High RCE via authentication bypass in Desktop Central
Patterns: repeated unpatched RCE vulnerabilities across multiple product lines; reliance on vulnerable third-party dependencies (e.g., Apache Santuario); authentication bypasses enabling arbitrary code execution
FAILURE HISTORY · 9
DATEEVENTSEVSUMMARY
2021-11-03 CVE-2021-40539 critical Zoho's ManageEngine ADSelfService Plus exposed via unpatched RCE flaw exploited in the wild
2023-01-23 CVE-2022-47966 critical Zoho ManageEngine products suffered an unauthenticated remote code execution vulnerability due to an outdated third-party dependency, Apache Santuario.
2021-11-03 CVE-2020-10189 high Unauthenticated remote code execution via file upload in Zoho ManageEngine Desktop Central.
2021-12-01 CVE-2021-44077 high Unauthenticated remote code execution in Zoho ManageEngine ServiceDesk Plus allowed attackers to execute arbitrary code on vulnerable systems.
2021-12-10 CVE-2021-44515 high Zoho Desktop Central had an authentication bypass vulnerability allowing arbitrary code execution on the MSP server.
2023-03-07 CVE-2022-28810 high Zoho's ManageEngine ADSelfService Plus exposed RCE due to unpatched vulnerability during password change/reset, exploited in the wild.
2022-09-22 CVE-2022-35405 high Zoho ManageEngine PAM360, Password Manager Pro, and Access Manager Plus allow remote code execution due to unpatched vulnerabilities.
2021-12-01 CVE-2021-37415 high An authentication bypass in Zoho ManageEngine ServiceDesk Plus allowed unauthenticated access to REST-API URLs, enabling attackers to bypass login and potentially access sensitive IT service data.
2021-11-03 CVE-2019-8394 high Remote attackers exploited an unspecified file upload vulnerability in Zoho ManageEngine ServiceDesk Plus to upload files via the login page customization feature.
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.60
Critical authentication bypass flaw in Zoho Desktop Central allowed arbitrary code execution, leading to data breaches in fintech firms and drawing negative attention from security press and governmen
synthesissevere-fallout-0.60
High-severity unauthenticated RCE in widely deployed ITSM software, CVSS 9.8, no praise for handling in provided sources.
synthesissevere-fallout-0.60
Authentication bypass in enterprise service desk software is a critical flaw with severe fallout, though the provided source is purely factual without commentary.
synthesissevere-fallout-0.60
Vulnerability allows remote code execution via authentication bypass, representing a critical security failure with severe implications for enterprise environments relying on the product.
synthesissevere-fallout-0.60
Unauthenticated RCE in a widely deployed enterprise management tool is a critical failure, though Zoho's response was relatively swift.
synthesissevere-fallout-0.60
Vulnerability allowed remote file uploads via login customization, posing significant security risks to enterprise users relying on Zoho's SDP for IT service management.
NVD ↗severe-fallout+0.00
No coverage
cooey ↗severe-fallout-0.50
Neutral technical record
"Zoho Desktop Central contains an authentication bypass vulnerability that could allow an attacker to execute arbitrary code in the Desktop Central MSP server."
www.upguard.com ↗severe-fallout+0.00
No coverage
CISA ↗severe-fallout+0.00
No coverage
cybernews.com ↗severe-fallout-0.80
Negative press
"Fintech firms suffer data breach due to critical Zoho flaw"
www.cve.org ↗severe-fallout+0.00
No coverage
NIST ↗severe-fallout+0.00
NIST NVD page, no direct sentiment.
xposedornot.com ↗severe-fallout+0.00
Data breach directory, no direct vendor sentiment.
SentinelOne ↗severe-fallout+0.00
Vendor security page, no direct sentiment.
securityonline.info ↗severe-fallout+0.00
Security news site, no direct sentiment.
cooey ↗severe-fallout+0.00
neutral
"Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication"
cooey ↗severe-fallout-0.60
NVD confirms unauthenticated RCE, no positive handling noted.
"Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution"
sploitus.com ↗severe-fallout-0.80
CVSS 9.8 pre-auth RCE, no vendor praise.
"Pre-auth RCE in ManageEngine ServiceDesk Plus below build 11306. Unauthenticated upload of msiexec.exe via ImportTechnicians (multipart form-data) leading to RCE."
cooey ↗severe-fallout-0.60
Vulnerability allowed remote file uploads via login customization, posing significant security risks to enterprise users relying on Zoho's SDP for IT service management.
"Zoho ManageEngine ServiceDesk Plus (SDP) contains an unspecified vulnerability that allows remote users to upload files via login page customization."
cooey ↗severe-fallout-0.60
Critical vulnerability allowing remote code execution via authentication bypass in REST API URLs, indicating a severe security flaw in the product.
"Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution."
cooey ↗severe-fallout-0.60
Critical vulnerability in a core management product, but no severe fallout or condemnation is evident in the provided text.
Open questions: Zoho's current patching SLA for ManageEngine products · Whether Zoho has implemented dependency scanning for third-party libraries
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-17 04:11:21.561247+00:00