A critical unauthenticated remote code execution (RCE) vulnerability, tracked as CVE-2026-6516, affects ManageEngine ADAudit Plus versions prior to 8606. The flaw stems from improper validation in the agent API, allowing attackers to execute arbitrary code without authentication. Successful exploitation could lead to full system compromise, data exfiltration, or lateral movement within networks. All deployments of ADAudit Plus with version numbers below 8606 are affected. Given the severity (CVSS score 10.0) and potential for remote code execution without user interaction, exploitation is highly likely in targeted attacks. Immediate remediation is required. Administrators should apply the vendor-provided patch to version 8606 or later. Until patched, restrict network access to the agent API and monitor for suspicious activity. This vulnerability underscores the importance of timely patch management for enterprise security tools.
CRITICAL
CVSS 10.0
CVE-2026-6516
2026-08-13
Critical RCE Vulnerability in ManageEngine ADAudit Plus (CVE-2026-6516)
ManageEngine ADAudit Plus versions before 8606 contain an unauthenticated remote code execution vulnerability in the agent API. Attackers can exploit this to execute arbitrary code. Immediate patching is required to mitigate critical risks.