Zoho vendor intelligence
Zoho Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting Zoho products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 14
- Known exploited vulnerabilities affecting Zoho products
- In CISA KEV
- 9
- Records also listed in the official catalog
- Beyond CISA KEV
- 5
- Additional exploited CVEs absent from CISA KEV
- Sensor Observed
- 0
- Zoho KEVs with sensor-observed exploitation activity
The catalog gap matters for Zoho exposure
Five of the fourteen exploited Zoho CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 36% of this vendor portfolio.
- 64%
- Covered by CISA
- 36%
- Beyond CISA
- 10
- Product families
Attested Zoho CVEs
Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2022-36923
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before... |
ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, OpUtils | High | Beyond CISA | 25 Jan 2026 |
|
CVE-2022-29081
Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control... |
["ManageEngine Access Manager Plus", "Password Manager Pro", "PAM360"] | High | Beyond CISA | 01 Dec 2025 |
|
CVE-2022-28219
Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution. |
ManageEngine ADAudit Plus | High | Beyond CISA | 04 Aug 2025 |
|
CVE-2019-8394
Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization. |
ManageEngine ServiceDesk Plus | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-10189
Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the... |
ManageEngine Desktop Central | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-40539
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution. |
ManageEngine ADSelfService Plus | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-44077
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to... |
ManageEngine ServiceDesk Plus, ManageEngine ServiceDesk Plus MSP, ManageEngine SupportCenter Plus | Confirmed | In CISA | 01 Dec 2021 |
|
CVE-2021-37415
Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication. |
ManageEngine ServiceDesk Plus | Confirmed | In CISA | 01 Dec 2021 |
|
CVE-2021-44515
Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in the wild... |
ManageEngine Desktop Central | Confirmed | In CISA | 10 Dec 2021 |
|
CVE-2022-35405
Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also... |
ManageEngine Password Manager Pro, PAM360, Access Manager Plus | Confirmed | In CISA | 22 Sep 2022 |
|
CVE-2022-47966
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario... |
ManageEngine | Confirmed | In CISA | 23 Jan 2023 |
|
CVE-2022-28810
Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as... |
ManageEngine ADSelfService Plus | Confirmed | In CISA | 07 Mar 2023 |
|
CVE-2021-3287
Zoho ManageEngine OpManager before 12.5.329 allows unauthenticated Remote Code Execution due to a general bypass in the deserialization class. |
ManageEngine OpManager | High | Beyond CISA | 22 Apr 2021 |
|
CVE-2018-17283
Zoho ManageEngine OpManager before 12.3 Build 123196 does not require authentication for /oputilsServlet requests, as demonstrated by a... |
ManageEngine OpManager | High | Beyond CISA | 21 Sep 2018 |
No Zoho CVEs match this search or filter.
Showing 14 of 14 Zoho known exploited vulnerabilities.
Recurring weakness patterns
Deserialization, missing authentication for critical function, and access control account for six mapped occurrences across this Zoho KEV portfolio.
CWE-502
Deserialization of Untrusted Data
CWE-306
Missing Authentication for Critical Function
CWE-284
Improper Access Control
CWE-434
Unrestricted Upload of File with Dangerous Type
CWE-611
Improper Restriction of XML External Entity Reference
CWE-706
Use of Incorrectly-Resolved Name or Reference
CWE-798
Use of Hard-coded Credentials
CWE-20
Improper Input Validation
Early warning alerts
Get alerts on high-impact exploitation
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.