FAIL › dossier
Zoho
VENDOR· dossier confidence 20%
Zoho ManageEngine is a vendor of IT management and endpoint security software with a documented history of critical and high-severity remote code execution vulnerabilities. Their security posture is compromised by a pattern of unpatched dependencies and authentication bypasses that allow attackers to execute arbitrary code across their product portfolio.
PROFILE
CategoryIT Management & Endpoint SecurityWhat they doZoho ManageEngine provides IT management, endpoint security, and identity management software solutions for enterprises.
Websitehttps://www.manageengine.com ↗
SECURITY POSTURE
The company has a poor security track record characterized by a high frequency of critical and high-severity remote code execution (RCE) vulnerabilities across its ManageEngine product line, often stemming from unpatched dependencies, authentication bypasses, and file upload flaws.
Notable failures
- CVE-2021-40539: Critical RCE via authentication bypass in ADSelfService Plus
- CVE-2022-47966: Critical RCE via outdated Apache Santuario dependency
- CVE-2021-44515: High RCE via authentication bypass in Desktop Central
Patterns: repeated unpatched RCE vulnerabilities across multiple product lines; reliance on vulnerable third-party dependencies (e.g., Apache Santuario); authentication bypasses enabling arbitrary code execution
FAILURE HISTORY · 9
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2021-11-03 | CVE-2021-40539 | critical | Zoho's ManageEngine ADSelfService Plus exposed via unpatched RCE flaw exploited in the wild |
| 2023-01-23 | CVE-2022-47966 | critical | Zoho ManageEngine products suffered an unauthenticated remote code execution vulnerability due to an outdated third-party dependency, Apache Santuario. |
| 2021-11-03 | CVE-2020-10189 | high | Unauthenticated remote code execution via file upload in Zoho ManageEngine Desktop Central. |
| 2021-12-01 | CVE-2021-44077 | high | Unauthenticated remote code execution in Zoho ManageEngine ServiceDesk Plus allowed attackers to execute arbitrary code on vulnerable systems. |
| 2021-12-10 | CVE-2021-44515 | high | Zoho Desktop Central had an authentication bypass vulnerability allowing arbitrary code execution on the MSP server. |
| 2023-03-07 | CVE-2022-28810 | high | Zoho's ManageEngine ADSelfService Plus exposed RCE due to unpatched vulnerability during password change/reset, exploited in the wild. |
| 2022-09-22 | CVE-2022-35405 | high | Zoho ManageEngine PAM360, Password Manager Pro, and Access Manager Plus allow remote code execution due to unpatched vulnerabilities. |
| 2021-12-01 | CVE-2021-37415 | high | An authentication bypass in Zoho ManageEngine ServiceDesk Plus allowed unauthenticated access to REST-API URLs, enabling attackers to bypass login and potentially access sensitive IT service data. |
| 2021-11-03 | CVE-2019-8394 | high | Remote attackers exploited an unspecified file upload vulnerability in Zoho ManageEngine ServiceDesk Plus to upload files via the login page customization feature. |
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.60
Critical authentication bypass flaw in Zoho Desktop Central allowed arbitrary code execution, leading to data breaches in fintech firms and drawing negative attention from security press and governmen
synthesissevere-fallout-0.60
High-severity unauthenticated RCE in widely deployed ITSM software, CVSS 9.8, no praise for handling in provided sources.
synthesissevere-fallout-0.60
Authentication bypass in enterprise service desk software is a critical flaw with severe fallout, though the provided source is purely factual without commentary.
synthesissevere-fallout-0.60
Vulnerability allows remote code execution via authentication bypass, representing a critical security failure with severe implications for enterprise environments relying on the product.
synthesissevere-fallout-0.60
Unauthenticated RCE in a widely deployed enterprise management tool is a critical failure, though Zoho's response was relatively swift.
synthesissevere-fallout-0.60
Vulnerability allowed remote file uploads via login customization, posing significant security risks to enterprise users relying on Zoho's SDP for IT service management.
No coverage
Neutral technical record
"Zoho Desktop Central contains an authentication bypass vulnerability that could allow an attacker to execute arbitrary code in the Desktop Central MSP server."
No coverage
No coverage
Negative press
"Fintech firms suffer data breach due to critical Zoho flaw"
No coverage
NIST NVD page, no direct sentiment.
Data breach directory, no direct vendor sentiment.
Vendor security page, no direct sentiment.
Security news site, no direct sentiment.
neutral
"Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication"
NVD confirms unauthenticated RCE, no positive handling noted.
"Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution"
CVSS 9.8 pre-auth RCE, no vendor praise.
"Pre-auth RCE in ManageEngine ServiceDesk Plus below build 11306. Unauthenticated upload of msiexec.exe via ImportTechnicians (multipart form-data) leading to RCE."
Vulnerability allowed remote file uploads via login customization, posing significant security risks to enterprise users relying on Zoho's SDP for IT service management.
"Zoho ManageEngine ServiceDesk Plus (SDP) contains an unspecified vulnerability that allows remote users to upload files via login page customization."
Critical vulnerability allowing remote code execution via authentication bypass in REST API URLs, indicating a severe security flaw in the product.
"Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution."
Critical vulnerability in a core management product, but no severe fallout or condemnation is evident in the provided text.
DOSSIER SOURCES
- Zoho MCP Server Integration - ManageEngine · www.manageengine.com
- ManageEngine Status. Check if ManageEngine is down or ... - StatusGator · statusgator.com
- Patch Tuesday: July 2026 Latest Patch Updates & Breakdown - ManageEngine · www.manageengine.com
Open questions: Zoho's current patching SLA for ManageEngine products · Whether Zoho has implemented dependency scanning for third-party libraries
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-17 04:11:21.561247+00:00