A critical unauthenticated remote code execution (RCE) vulnerability, tracked as CVE-2026-6516, affects ManageEngine ADAudit Plus versions prior to 8606. The flaw stems from improper validation in the agent API, allowing attackers to execute arbitrary code without authentication. Successful exploitation could lead to full system compromise, data exfiltration, or lateral movement within networks. All deployments of ADAudit Plus with version numbers below 8606 are affected. Given the severity (CVSS score 10.0) and potential for remote code execution without user interaction, exploitation is highly likely in targeted attacks. Immediate remediation is required. Administrators should apply the vendor-provided patch to version 8606 or later. Until patched, restrict network access to the agent API and monitor for suspicious activity. This vulnerability underscores the importance of timely patch management for enterprise security tools.