← Back to search

CVE-2026-74849

9.8 CRITICAL

Published 2026-09-22 · Updated 2026-09-23

AI risk analysis

Summary
This vulnerability allows remote code execution in Zohocorp ManageEngine ADSelfService Plus versions before build 7001, posing a significant risk to system security.
Exploitability
Exploitation is relatively straightforward with no preconditions required, making it a high-risk vulnerability.
Blast radius
If exploited, this could lead to complete control of the affected system, including data theft and further lateral movement.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to build 7001 or later.
rceremote-code-executionwebpatch

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to a remote code execution vulnerability in the GINA client.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-78

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.