ManageEngine ADAudit Plus RCE Vulnerability - 20260724001¶
Overview¶
A critical unauthenticated remote code execution (RCE) vulnerability has been identified in ManageEngine ADAudit Plus. Successful exploitation could allow a remote attacker to execute arbitrary code on the affected server without authentication, potentially leading to full system compromise.
What is vulnerable?¶
| Product(s) Affected | Version(s) | CVE | CVSS | Severity |
|---|---|---|---|---|
| ManageEngine ADAudit Plus | All versions prior to Build 8606 | CVE-2026-6516 | 10 | Critical |
What has been observed?¶
The WASOC has not received any reports of exploitation of this vulnerability on Western Australian Government networks at the time of writing.
Recommendation¶
The WASOC recommends administrators apply the solutions as per vendor instructions to all affected devices within expected timeframes (refer Patch Management):