CVE-2022-28219 is a critical vulnerability in Zoho ManageEngine ADAudit Plus (builds prior to 7060) that allows unauthenticated remote code execution. The vulnerability is the result of a chained attack involving a blind XML External Entity (XXE) injection in the /api/agent/tabs/agentData endpoint and a Java deserialization flaw in the /cewolf endpoint. An attacker can use the XXE to plant a malicious file and enumerate directories, then leverage the deserialization bug to execute arbitrary code as the ADAudit Plus service user. The attack does not require authentication and can be performed remotely. Proof-of-concept exploits are publicly available.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module targeting ManageEngine ADAudit Plus (versions prior to build 7060) for CVE-2022-28219. The exploit leverages two vulnerabilities: a path traversal in the /cewolf endpoint and a blind XML External Entity (XXE) in /api/agent/tabs/agentData, to upload and execute arbitrary code on the target Windows system. The module is highly weaponized, supporting customizable command payloads and using Metasploit's staging and handler infrastructure. The attacker must be able to connect to the target's HTTP service (default port 8081) and run attacker-controlled HTTP/FTP servers to deliver the payload. The code is written in Ruby and follows standard Metasploit module structure, with options for endpoint paths, domain, and callback ports. The main exploit file is 'modules/exploits/windows/http/manageengine_adaudit_plus_cve_2022_28219.rb'.
This repository contains a Python proof-of-concept exploit for CVE-2022-28219, a critical XXE and Java deserialization vulnerability in ManageEngine ADAudit Plus (builds < 7060). The main file, CVE-2022-28219.py, is a standalone exploit script that can perform arbitrary file reads and remote code execution (RCE) on vulnerable targets. It works by sending crafted XML payloads to the target's web interface, leveraging XXE to leak files and, if possible, escalate to RCE via Java deserialization. The script sets up local HTTP and FTP servers to deliver malicious DTDs/JARs and receive exfiltrated data. The README provides usage instructions and mitigation advice. No framework is used; the exploit is fully self-contained in Python. The LICENSE is Apache 2.0. The exploit is operational and can be used for both file disclosure and command execution, provided the target is running a vulnerable version and Java runtime.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.