securityonline.info 22 Sept 2026, 16:23 UTC

Zoho Fixes Critical ManageEngine Flaw Allowing System Takeover

Zoho Fixes Critical ManageEngine Flaw Allowing System Takeover
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

ZOHO Corporation has patched a critical vulnerability in the GINA client used by ManageEngine ADSelfService Plus. Tracked as CVE-2026-74849, the flaw has a CVSSv3 score of 9.8 and affects deployments using the Windows logon-screen client before build 7001. An attacker with physical or remote access to the Windows logon screen could exploit the embedded kiosk browser and execute arbitrary commands with NT AUTHORITY\SYSTEM privileges, potentially resulting in complete host compromise. Systems using only the standard web portal are not affected by this specific attack route.

According to the report, the vulnerability involves incorrect error handling in the embedded browser. By manipulating its interface, an unauthenticated attacker could bypass sandbox restrictions and cause the underlying application to run commands. The report says there is no confirmed exploitation in the wild and no public proof-of-concept code. Administrators should update ADSelfService Plus to build 7001 or later, which corrects the error handling and adds hardening for the logon-screen browser. No temporary workaround is available other than removing the GINA client from endpoints.

View full article

Article by CyberSIXT