CVE-2026-6516: Remote Code Execution
Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ManageEngine ADAudit Plusto a version that resolves this vulnerability.Fixed in 8606 - Compensating control
Restrict network access to the ADAudit Plus vulnerable agent API from untrusted networks (e.g., allow only trusted hosts) to mitigate unauthenticated remote code execution exposure.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6516?
The severity of CVE-2026-6516 is rated as critical with a score of 10.
What type of vulnerability is CVE-2026-6516?
CVE-2026-6516 is classified as a Remote Code Execution vulnerability due to OS Command Injection.
How do I fix CVE-2026-6516?
To mitigate CVE-2026-6516, upgrade to Zohocorp ManageEngine ADAudit Plus version 8606 or later.
What are the affected versions for CVE-2026-6516?
Zohocorp ManageEngine ADAudit Plus versions prior to 8606 are affected by CVE-2026-6516.
Can CVE-2026-6516 be exploited remotely?
Yes, CVE-2026-6516 can be exploited remotely due to unauthenticated access via the vulnerable agent API.