Skip to content

ManageEngine ADAudit Plus RCE Vulnerability - 20260724001

Overview

A critical unauthenticated remote code execution (RCE) vulnerability has been identified in ManageEngine ADAudit Plus. Successful exploitation could allow a remote attacker to execute arbitrary code on the affected server without authentication, potentially leading to full system compromise.

What is vulnerable?

Product(s) Affected Version(s) CVE CVSS Severity
ManageEngine ADAudit Plus All versions prior to Build 8606 CVE-2026-6516 10 Critical

What has been observed?

The WASOC has not received any reports of exploitation of this vulnerability on Western Australian Government networks at the time of writing.

Recommendation

The WASOC recommends administrators apply the solutions as per vendor instructions to all affected devices within expected timeframes (refer Patch Management):

Additional References