securityonline.info 7/24/2026, 3:10:34 AM · external

ADAudit Plus Flaw CVE-2026-6516 Allows Unauthenticated Remote Code Execution at CVSS 10

ADAudit Plus Flaw CVE-2026-6516 Allows Unauthenticated Remote Code Execution at CVSS 10
CyberSIXT Evidence Panel
Primary Source manageengine.com
CISA KEV Not in KEV
Patch Patch Status Unknown

A critical vulnerability in ManageEngine ADAudit Plus, tracked as CVE-2026-6516, allows unauthenticated remote code execution due to weaknesses in the product's Agent APIs. An authentication bypass and a path traversal flaw enable attackers to execute code without valid credentials. This issue has a CVSS score of 10 and affects all builds below 8606. The vulnerability was patched in build 8606, released on April 17, 2026, but there have been no reported exploits in the wild. Users are urged to update their systems immediately to mitigate risks.

View Primary Source Via securityonline.info

Article by CyberSIXT