CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-6516

criticalCVSS 10covered by 2 sourcesfirst seen 2026-07-23
ZohoCorp has fixed a vulnerability in ManageEngine ADAudit Plus. The vulnerability is located in the agent API of ManageEngine ADAudit Plus versions earlier than 8606. Due to improper validation in the API, attackers can execute arbitrary code remotely without authentication. All implementations with vulnerable versions are affected. ADAudit Plus is a tool that should not be publicly available. It is good practice to support such management tooling in a separate management environment. This limits the potential for large-scale exploitation.

CSIRTS triage

What
Improper validation in the agent API allows attackers to execute arbitrary code remotely without authentication.
Who is affected
All implementations of ManageEngine ADAudit Plus versions earlier than 8606 are affected.
Urgency
Remediation is critical due to the potential for remote code execution without authentication.
Action
Upgrade to version 8606 or later to address this vulnerability.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-6516

Get an email if CVE-2026-6516 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-6516

CVE.org record

Embed the live status

CVE-2026-6516 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-6516 status](https://www.csirts.com/badge/CVE-2026-6516)](https://www.csirts.com/cve/CVE-2026-6516)