Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Flaw in ManageEngine AD360 Risks User Data

Critical Flaw in ManageEngine AD360 Risks User Data

Posted on June 25, 2026 By CWS

ManageEngine has recently identified a critical security vulnerability, labeled CVE-2026-11374, within its identity and access management solutions integrated with AD360. This flaw, if exploited, could allow unauthorized attackers to predict single sign-on (SSO) tokens, potentially leading to account takeovers and exposure of sensitive user data.

Impact on Identity Management Solutions

The vulnerability affects several key ManageEngine products, including ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, when used within the AD360 environment. These tools are vital for enterprise identity governance, Active Directory management, auditing, and Microsoft 365 administration. Therefore, this flaw poses a significant risk, especially in large-scale deployments.

Security researcher 0xmanhnv discovered this vulnerability and reported it through the Zoho BugBounty program. ManageEngine has acknowledged the researcher’s role in responsibly disclosing the issue.

Technical Details of the Vulnerability

The vulnerability arises from weaknesses in SSO ticket generation during authentication. When users log in through AD360’s SSO, tokens are issued to validate sessions. Unfortunately, researchers found that these tokens could be predicted by unauthenticated attackers, allowing them to craft valid session tokens without needing legitimate credentials.

This predictability enables attackers to impersonate users, gaining unauthorized access to systems. Such access could expose user identities and role-based access information, potentially leading to privilege escalation.

In environments where AD360 serves as a central identity hub, the risk escalates as multiple integrated services can be compromised through a single successful attack. Attackers could access ADAudit Plus audit logs and administrative data, facilitating internal reconnaissance and potential lateral movement within an organization.

Mitigation and Security Recommendations

ManageEngine has released patches to rectify this vulnerability in versions issued between June 3 and June 12, 2026. Affected products include ADSelfService Plus version 6528 and earlier, RecoveryManager Plus version 6320 and earlier, M365 Manager Plus version 4816 and earlier, and ADAudit Plus version 8702 and earlier. The updates enhance SSO ticket generation mechanisms to prevent predictability.

Organizations using these products are strongly advised to apply the latest service packs immediately to secure their systems. Additionally, security teams should actively monitor authentication logs for unusual SSO activities and reassess access permissions on critical accounts.

Improving access controls and minimizing the exposure of identity services can further mitigate exploitation risks. Stay informed by following us on Google News, LinkedIn, and X for more instant updates.

Cyber Security News Tags:AD360, Cybersecurity, data protection, enterprise security, identity management, ManageEngine, patch update, SSO security, user data exposure, Vulnerability

Post navigation

Previous Post: GitLab Releases Updates for Critical Security Flaws
Next Post: Navigating the Mythos Era with Network Detection and Response

Related Posts

Rise in Phishing Activity Using Spoofed SharePoint Domains With Sneaky2FA Techniques Rise in Phishing Activity Using Spoofed SharePoint Domains With Sneaky2FA Techniques Cyber Security News
AI-Powered Cyber Attacks Accelerate Threat Landscape AI-Powered Cyber Attacks Accelerate Threat Landscape Cyber Security News
Hackers Can Attack Active Directory Sites to Escalate Privileges and Compromise the Domain Hackers Can Attack Active Directory Sites to Escalate Privileges and Compromise the Domain Cyber Security News
Critical Vulnerability in Paloalto Cortex XDR Broker Critical Vulnerability in Paloalto Cortex XDR Broker Cyber Security News
Women’s Dating App Tea Exposes Selfie Images of 13,000 Users Women’s Dating App Tea Exposes Selfie Images of 13,000 Users Cyber Security News
Top 10 Best Next‑Generation Firewall (NGFW) Providers in 2025 Top 10 Best Next‑Generation Firewall (NGFW) Providers in 2025 Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Runlayer Secures $30M in Series A Funding Boost
  • Smart TV Proxyware and AI in Cybercrime: Key Updates
  • Gemini 3.5 Flash: AI Agents in Computing Environments
  • Cal Water Cyberattack Investigation Reveals No OT Breach
  • Navigating the Mythos Era with Network Detection and Response

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Runlayer Secures $30M in Series A Funding Boost
  • Smart TV Proxyware and AI in Cybercrime: Key Updates
  • Gemini 3.5 Flash: AI Agents in Computing Environments
  • Cal Water Cyberattack Investigation Reveals No OT Breach
  • Navigating the Mythos Era with Network Detection and Response

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark