CVE-2026-2740
Published: May 21, 2026
Modified: May 22, 2026
CVSS v3.1
8.4
Description
Zohocorp ManageEngine ADSelfService Plus version before 6525, DataSecurity Plus before 6264 and RecoveryManager Plus before 6313 are vulnerable to Authenticated Remote code execution in the agent machines due to the bug in the 3rd party dependency.
| Vendor | Product | Versions |
|---|---|---|
Zohocorp | ManageEngine ADSelfService Plus | affected 0 - < 6525 |
Zohocorp | ManageEngine DataSecurity Plus | affected 0 - < 6264 |
Zohocorp | ManageEngine RecoveryManager Plus | affected 0 - < 6313 |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now