AI description
CVE-2026-6516 describes an unauthenticated remote code execution (RCE) vulnerability found in Zohocorp ManageEngine ADAudit Plus, affecting all builds prior to 8606. This flaw resides within the product's agent API and is a result of chaining two distinct weaknesses: an authentication bypass and a path traversal vulnerability. By exploiting these combined weaknesses, a remote and unauthenticated attacker can execute arbitrary code on the ADAudit Plus server. The vendor released a fix for this vulnerability in build 8606 on April 17, 2026.
- Description
- Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.
- Source
- 0fc0942c-577d-436f-ae8e-945763c79b02
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 10
- Impact score
- 6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
- Severity
- CRITICAL
- 0fc0942c-577d-436f-ae8e-945763c79b02
- CWE-78
- Hype score
- Not currently trending
Top #CVE to #patch this week 👀 - @VMware #ESXi 9.0 RCE (CVE-2026-47876, CVE-2026-41703) - @JetBrains #TeamCity RCE (CVE-2026-63077, CVE-2026-65907) - #Jenkins Core (CVE-2026-70426) - @zohocorp ManageEngine ADAudit RCE (CVE-2026-6516) - @IBM Langflow RCE (CVE-2026-9198) -
@stansecure
13 Aug 2026
51 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🚨 CVE-2026-6516: Remote Code Execution Critical Vulnerability Alert! ADAudit is affected by CVE-2026-6516. Full Vulnerability Details & Analysis at DarkEye: 🔗 https://t.co/kNHHXg5wqh 🔍 Identify Targets via ZoomEye: Filter: vul.cve="CVE-2026-6516" Search Dork: htt
@zoomeye_team
27 Jul 2026
3210 Impressions
3 Retweets
18 Likes
12 Bookmarks
0 Replies
0 Quotes