Zoho Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Zoho products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

14

In CISA KEV

9

Beyond CISA KEV

5

Sensor Observed

0

Virtual Patch Available

0

Zoho KEVs Added by Year

Loading...

14 Zoho KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2022-36923

Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before...

High Not in CISA 25 Jan 2026
CVE-2022-29081

Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control...

High Not in CISA 01 Dec 2025
CVE-2022-28219

Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution.

High Not in CISA 04 Aug 2025
CVE-2019-8394

Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization.

Confirmed In CISA 03 Nov 2021
CVE-2020-10189

Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the...

Confirmed In CISA 03 Nov 2021
CVE-2021-40539

Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution.

Confirmed In CISA 03 Nov 2021
CVE-2021-44077

Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to...

Confirmed In CISA 01 Dec 2021
CVE-2021-37415

Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication.

Confirmed In CISA 01 Dec 2021
CVE-2021-44515

Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in the wild...

Confirmed In CISA 10 Dec 2021
CVE-2022-35405

Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also...

Confirmed In CISA 22 Sep 2022
CVE-2022-47966

Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario...

Confirmed In CISA 23 Jan 2023
CVE-2022-28810

Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as...

Confirmed In CISA 07 Mar 2023
CVE-2021-3287

Zoho ManageEngine OpManager before 12.5.329 allows unauthenticated Remote Code Execution due to a general bypass in the deserialization class.

High Not in CISA 22 Apr 2021
CVE-2018-17283

Zoho ManageEngine OpManager before 12.3 Build 123196 does not require authentication for /oputilsServlet requests, as demonstrated by a...

High Not in CISA 21 Sep 2018

Common Vulnerability Classes (CWE)

  • CWE-502 — Deserialization of Untrusted Data 3
  • CWE-306 — Missing Authentication for Critical Function 2
  • CWE-284 — Improper Access Control 1
  • CWE-434 — Unrestricted Upload of File with Dangerous Type 1
  • CWE-611 — Improper Restriction of XML External Entity Reference 1
  • CWE-706 — Use of Incorrectly-Resolved Name or Reference 1
  • CWE-798 — Use of Hard-coded Credentials 1
  • CWE-20 — Improper Input Validation 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology