ManageEngine has patched a critical unauthenticated remote code execution flaw in ADAudit Plus tracked as CVE-2026-6516, affecting all builds earlier than 8606. The vulnerability resides in the product's Agent API and stems from a chain involving an authentication bypass and a path traversal issue, enabling attackers to execute code remotely without credentials. The issue is classified under CWE-78, and public reporting lists a severe network-exploitable attack path with high confidentiality and integrity impact.
Zoho/ManageEngine assigned the flaw a CVSS 10.0 score and released a fix in build 8606, advising customers to update the ADAudit Plus server as well as affected Windows and Mac agents. The vendor said there was no confirmed exploitation in the wild and no public proof-of-concept at the time of disclosure. The vulnerability was reported by Linhlt of VCB.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-6516 was publicly listed as a vulnerability affecting ManageEngine ADAudit Plus versions before 8606, with unauthenticated remote code execution impact and CWE-78 mapping. The listing also referenced the vendor advisory for the issue.
Zoho/ManageEngine fixed CVE-2026-6516 in ADAudit Plus build 8606 on 17 April 2026. The vulnerability affects earlier builds and can enable unauthenticated remote code execution via Agent API weaknesses.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.