Brand
ManageEngine (Zoho): actively exploited vulnerabilities
9 vulnerabilities in ManageEngine (Zoho) products (ServiceDesk Plus, ADSelfService Plus, Endpoint Central (ex-Desktop Central)…) are in CISA’s catalog of exploited vulnerabilities. Last added: March 7, 2023.
The brand’s general security advisories page, not the advisory for a specific vulnerability (address checked September 28, 2026).
-
0 vulnerabilities added in the last 12 months
-
9 exploited vulnerabilities in the catalog, in total
-
0 added in the last 30 days
By category
Add just one ManageEngine (Zoho) category to your radar, or open its page.
- Monitoring, ITSM and asset management 6 vulnerabilities
- Identity and access 3 vulnerabilities
A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.
Affected products
Follow a single ManageEngine (Zoho) product (ServiceDesk Plus, ADSelfService Plus…) rather than the whole brand.
- ServiceDesk Plus3 vulnerabilities, Monitoring and ITSM
- ADSelfService Plus2 vulnerabilities, Identity and access
- Endpoint Central (ex-Desktop Central)2 vulnerabilities, Monitoring and ITSM
- PAM360 / Password Manager Pro1 vulnerability, Identity and access
- Multiple products1 vulnerability, Monitoring and ITSM
Name used by CISA: Zoho. Product families: indicative classification by this site.
Patch first
In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this ManageEngine (Zoho) list.
- Rank 1
ManageEngine (Zoho) Multiple productsCVE-2022-47966
Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability
Ransomware
CVSS severity 9.8critical
Added Jan 23, 2023
- Rank 2
ManageEngine (Zoho) PAM360 / Password Manager ProCVE-2022-35405
Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability
CVSS severity 9.8critical
Added Sep 22, 2022
- Rank 3
ManageEngine (Zoho) Endpoint Central (ex-Desktop Central)CVE-2021-44515
Zoho Desktop Central Authentication Bypass Vulnerability
CVSS severity 9.8critical
Added Dec 10, 2021
- Rank 4
ManageEngine (Zoho) ServiceDesk PlusCVE-2021-37415
Zoho ManageEngine ServiceDesk Authentication Bypass Vulnerability
CVSS severity 9.8critical
Added Dec 1, 2021
- Rank 5
ManageEngine (Zoho) ServiceDesk PlusCVE-2021-44077
Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability
CVSS severity 9.8critical
Added Dec 1, 2021
- Rank 6
ManageEngine (Zoho) Endpoint Central (ex-Desktop Central)CVE-2020-10189
Zoho ManageEngine Desktop Central File Upload Vulnerability
CVSS severity 9.8critical
Added Nov 3, 2021
- Rank 7
ManageEngine (Zoho) ADSelfService PlusCVE-2021-40539
Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability
Ransomware
CVSS severity 9.8critical
Added Nov 3, 2021
- Rank 8
ManageEngine (Zoho) ADSelfService PlusCVE-2022-28810
Zoho ManageEngine ADSelfService Plus Remote Code Execution Vulnerability
CVSS severity 6.8medium
Added Mar 7, 2023
- Rank 9
ManageEngine (Zoho) ServiceDesk PlusCVE-2019-8394
Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability
CVE from 2019, added in 2021
CVSS severity 6.5medium
Added Nov 3, 2021
Follow and verify
Get new ManageEngine (Zoho) vulnerabilities: RSS feed (add it to Outlook, Teams, Slack or your feed reader).
Indicative classification, based on the vendor and product names given by CISA. How products are classified.