Zoho users who did not install the security updates that addressed CVE-2022-47966 (CVSS score: 9.8), a pre-authentication remote code execution vulnerability in 24 different Zoho products that use the company’s ManageEngine, are vulnerable to another attack from multiple threat actors.
Threat actors are exploiting unpatched ManageEngine instances. CISA adds the vulnerability to its catalog and Zoho urges customers to check their deployments.
Threat actors are exploiting unpatched ManageEngine instances. CISA adds the vulnerability to its catalog and Zoho urges customers to check their deployments.
The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical severity Java deserialization vulnerability affecting multiple Zoho ManageEngine products to its catalog of bugs exploited in the wild.