• Home
    • What is
    • Computer security
      • Windows security
      • Mac security
      • Linux security
    • Mobile security
      • Android security
      • iOS Security
    • Data security
    • SCCM
    • Reviews
      • Case studies
    • Advertise
    • Contact
      • Privacy Policy
  • Subscribe now

    Loading
  • Home
  • What is
  • Computer security
    • Windows security
    • Mac security
    • Linux security
  • Mobile security
    • Android security
    • iOS Security
  • Data security
  • SCCM
  • Reviews
    • Case studies
  • Advertise
  • Contact
    • Privacy Policy
Home » Breaking Computer security Cyber Security data security Latest Cybersecurity News Linux security Mac security Windows security

Zoho ManageEngine vulnerability used in the RCE attacks

William Marshal Posted On September 23, 2022
0



Zoho ManageEngine Vulnerability

The CISA has alerted the IT community for  a critical Java deserialization vulnerability affecting several Zoho ManageEngine solutions. The security flaw CVE-2022-35405 can be exploited without  user interactions and perform remote code execution on devices that has the following Zoho ManageEngine products – PAM360, Password Manager Pro and Access Manager Plus.

The POC and a Metasploit module is disclosed since August for gaining RCE as the user. ManageEngine already warned its customers about the exploit in July.

Zoho ManageEngine vulnerability

CISA also did add this Zoho ManageEngine vulnerability to the known exploited vulnerabilities catalog, and ensured all the federal bodies are aware of it and patching the same.

The entities have until Oct 13th to ensure their networks are patched against those exploits.

Patching Zoho ManageEngine Vulnerability is a priority

The US Cybersecurity agency has strongly requested organizations across the nation to prioritize patching the exploit.

Since these types of exploits are the usual loophole for most cybersecurity incidents, the CISA is keen on ensuring the importance of patching them.

CISA has now added 800+ vulnerabilities to the list originally published, IT  professionals and admins are requested to keep track of the exploits and patch them as soon as possible.

Zoho ManageEnginne vulnerability is big as the vendor solution is widely used across geos including North American Region, and in recent times ManageEngine servers are constantly targeted with Desktop Central a.k.a Endpoint Central in particular.

Previously the tool was breached and the data associated with it was sold on hacker forums in July 2020.

APT27 hackers were the ones behind the breach, FBI and CISA released security advisories regarding the Zoho ManageEngine vulnerability that allowed dropping web shells on the networks of corporate network including healthcare, financial services, IT consulting and electronics industries.

Subscribe to our newsletter for daily alerts on cyber events, you can also follow us on Facebook, Linkedin, and Twitter.

You can reach out to us via Twitter/ Facebook or mail us at admin@thecybersecuritytimes.com for advertising requests.

Share the article with your friends


Cybersecuritydata securityvulnerability


Author

William Marshal

William has been one of the key contributors to 'The Cybersecurity Times' with 9.5 years of experience in the cybersecurity journalism. Apart from writing, he also like hiking, skating and coding.

You may also like
Top 9 Best Log Management Tools for 2025
September 20, 2025
Top 4 Remote Support Tools for 2025- Best Remote Support Solution
September 18, 2025
Top 5 Best Unified Endpoint Management (UEM) Software for 2025
September 12, 2025
Leave A Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

  • Subscribe to our newsletter

    Loading
  • Windows security

    • Top 9 Best Log Management Tools for 2025
      September 20, 2025
    • Top 4 Remote Support Tools for 2025- Best Remote Support...
      September 18, 2025
    • Top 5 Best Unified Endpoint Management (UEM) Software...
      September 12, 2025
    • Top 5 Threat Intelligence Tools For 2025
      July 25, 2025
    • Top 5 Best Microsoft Intune Alternatives to Consider...
      July 23, 2025


  • About us

    Our vision is to deliver the trending and happening cyber events to the enthusiasts.

    We believe in delivering educational and quality content for hassle-free understanding of the subject.

  • Subscribe to our newsletter

    Loading
  • Follow us

  • Advertise with us

    You can reach us via Facebook, Linkedin, or Twitter for advertising purposes.


© The Cybersecurity Times 2022. All rights reserved.
Press enter/return to begin your search