Skip to content
COOEY

FAIL › dossier

Zoho

VENDOR

· dossier confidence 20%

Zoho ManageEngine is a vendor of IT management and endpoint security software with a documented history of critical and high-severity remote code execution vulnerabilities. Their security posture is compromised by a pattern of unpatched dependencies and authentication bypasses that allow attackers to execute arbitrary code across their product portfolio.

PROFILE
CategoryIT Management & Endpoint SecurityWhat they doZoho ManageEngine provides IT management, endpoint security, and identity management software solutions for enterprises. Websitehttps://www.manageengine.com ↗
SECURITY POSTURE

The company has a poor security track record characterized by a high frequency of critical and high-severity remote code execution (RCE) vulnerabilities across its ManageEngine product line, often stemming from unpatched dependencies, authentication bypasses, and file upload flaws.

Notable failures
  • CVE-2021-40539: Critical RCE via authentication bypass in ADSelfService Plus
  • CVE-2022-47966: Critical RCE via outdated Apache Santuario dependency
  • CVE-2021-44515: High RCE via authentication bypass in Desktop Central
Patterns: repeated unpatched RCE vulnerabilities across multiple product lines; reliance on vulnerable third-party dependencies (e.g., Apache Santuario); authentication bypasses enabling arbitrary code execution
FAILURE HISTORY · 9
DATEEVENTSEVSUMMARY
2021-11-03 CVE-2021-40539 critical Zoho's ManageEngine ADSelfService Plus exposed via unpatched RCE flaw exploited in the wild
2023-01-23 CVE-2022-47966 critical Zoho ManageEngine products suffered an unauthenticated remote code execution vulnerability due to an outdated third-party dependency, Apache Santuario.
2021-11-03 CVE-2020-10189 high Unauthenticated remote code execution via file upload in Zoho ManageEngine Desktop Central.
2021-12-01 CVE-2021-44077 high Unauthenticated remote code execution in Zoho ManageEngine ServiceDesk Plus allowed attackers to execute arbitrary code on vulnerable systems.
2021-12-10 CVE-2021-44515 high Zoho Desktop Central had an authentication bypass vulnerability allowing arbitrary code execution on the MSP server.
2023-03-07 CVE-2022-28810 high Zoho's ManageEngine ADSelfService Plus exposed RCE due to unpatched vulnerability during password change/reset, exploited in the wild.
2022-09-22 CVE-2022-35405 high Zoho ManageEngine PAM360, Password Manager Pro, and Access Manager Plus allow remote code execution due to unpatched vulnerabilities.
2021-12-01 CVE-2021-37415 high An authentication bypass in Zoho ManageEngine ServiceDesk Plus allowed unauthenticated access to REST-API URLs, enabling attackers to bypass login and potentially access sensitive IT service data.
2021-11-03 CVE-2019-8394 high Remote attackers exploited an unspecified file upload vulnerability in Zoho ManageEngine ServiceDesk Plus to upload files via the login page customization feature.
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.60
Vulnerability allows remote code execution via authentication bypass, representing a critical security failure with severe implications for enterprise environments relying on the product.
synthesissevere-fallout-0.60
Unauthenticated RCE in a widely deployed enterprise management tool is a critical failure, though Zoho's response was relatively swift.
synthesissevere-fallout-0.60
Vulnerability allowed remote file uploads via login customization, posing significant security risks to enterprise users relying on Zoho's SDP for IT service management.
cooey ↗severe-fallout-0.60
Critical vulnerability allowing remote code execution via authentication bypass in REST API URLs, indicating a severe security flaw in the product.
"Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution."
cooey ↗severe-fallout-0.60
Critical vulnerability in a core management product, but no severe fallout or condemnation is evident in the provided text.
cooey ↗severe-fallout-0.60
Vulnerability allowed remote file uploads via login customization, posing significant security risks to enterprise users relying on Zoho's SDP for IT service management.
"Zoho ManageEngine ServiceDesk Plus (SDP) contains an unspecified vulnerability that allows remote users to upload files via login page customization."
Open questions: Zoho's current patching SLA for ManageEngine products · Whether Zoho has implemented dependency scanning for third-party libraries
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-17 04:11:21.561247+00:00