Zoho vendor intelligence

Zoho Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting Zoho products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Browse Zoho KEVs Full KEV feed
Total KEVs
14
Known exploited vulnerabilities affecting Zoho products
In CISA KEV
9
Records also listed in the official catalog
Beyond CISA KEV
5
Additional exploited CVEs absent from CISA KEV
Sensor Observed
0
Zoho KEVs with sensor-observed exploitation activity

The catalog gap matters for Zoho exposure

Five of the fourteen exploited Zoho CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 36% of this vendor portfolio.

64%
Covered by CISA
36%
Beyond CISA
10
Product families

Attested Zoho CVEs

Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2022-36923

Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before...

ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, OpUtils High Beyond CISA 25 Jan 2026
CVE-2022-29081

Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control...

["ManageEngine Access Manager Plus", "Password Manager Pro", "PAM360"] High Beyond CISA 01 Dec 2025
CVE-2022-28219

Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution.

ManageEngine ADAudit Plus High Beyond CISA 04 Aug 2025
CVE-2019-8394

Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization.

ManageEngine ServiceDesk Plus Confirmed In CISA 03 Nov 2021
CVE-2020-10189

Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the...

ManageEngine Desktop Central Confirmed In CISA 03 Nov 2021
CVE-2021-40539

Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution.

ManageEngine ADSelfService Plus Confirmed In CISA 03 Nov 2021
CVE-2021-44077

Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to...

ManageEngine ServiceDesk Plus, ManageEngine ServiceDesk Plus MSP, ManageEngine SupportCenter Plus Confirmed In CISA 01 Dec 2021
CVE-2021-37415

Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication.

ManageEngine ServiceDesk Plus Confirmed In CISA 01 Dec 2021
CVE-2021-44515

Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in the wild...

ManageEngine Desktop Central Confirmed In CISA 10 Dec 2021
CVE-2022-35405

Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also...

ManageEngine Password Manager Pro, PAM360, Access Manager Plus Confirmed In CISA 22 Sep 2022
CVE-2022-47966

Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario...

ManageEngine Confirmed In CISA 23 Jan 2023
CVE-2022-28810

Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as...

ManageEngine ADSelfService Plus Confirmed In CISA 07 Mar 2023
CVE-2021-3287

Zoho ManageEngine OpManager before 12.5.329 allows unauthenticated Remote Code Execution due to a general bypass in the deserialization class.

ManageEngine OpManager High Beyond CISA 22 Apr 2021
CVE-2018-17283

Zoho ManageEngine OpManager before 12.3 Build 123196 does not require authentication for /oputilsServlet requests, as demonstrated by a...

ManageEngine OpManager High Beyond CISA 21 Sep 2018

Showing 14 of 14 Zoho known exploited vulnerabilities.

Recurring weakness patterns

Deserialization, missing authentication for critical function, and access control account for six mapped occurrences across this Zoho KEV portfolio.

Browse all KEVs →

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.