Zoho users at risk of attack due to an unpatched vulnerability
Zoho users who did not install the security updates that addressed CVE-2022-47966 (CVSS score: 9.8), a pre-authentication remote code execution vulnerability in 24 different Zoho products that use the company’s ManageEngine, are vulnerable to another attack from multiple threat actors.
Apache Santuario Manageengine Onpremise Access Manager Plus Service Plus Password Manager Pro Remote Access Plus
Source: itworldcanada.com