External risk intelligence

ManageEngine ADAudit Plus Unauthenticated Remote Code Execution Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-6516

ManageEngine ADAudit Plus is a centralized auditing application typically deployed as a network-accessible service. Because this vulnerability allows unauthenticated remote code execution via the agent API, and the application is often reachable across corporate networks to facilitate auditing, the attack surface is significant.

OS Command Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability in ManageEngine ADAudit Plus allows unauthenticated remote code execution, meaning an attacker could potentially gain control of affected systems without needing any credentials. This could have significant implications for the confidentiality, integrity, and availability of your IT environment.

  • Unauthenticated attackers can run code remotely.
  • Affects systems that audit Active Directory.
  • Confirm relevance and exposure across your environment.

Attack Path

How an attacker could exploit the issue

An attacker can initiate an attack by sending specially crafted requests to the agent API of ManageEngine ADAudit Plus, even without any prior authentication. This interaction targets a vulnerability within the API, which, when triggered, can allow an attacker to execute arbitrary code remotely. This capability could potentially lead to a compromise of the system's confidentiality, integrity, and availability.

  • No authentication is required to start.
  • A vulnerable agent API is the trigger point.
  • Risk includes remote code execution.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, an unauthenticated remote code execution vulnerability in the agent API of ManageEngine ADAudit Plus could allow an attacker to execute arbitrary code on the affected system. This could potentially impact the integrity and availability of the service.

  • System data and service behavior could be affected.
  • Exposure could happen via the agent API over the network.
  • Malicious code execution on the affected system.

Operational Fix

Recommended remediation, mitigation, and detection steps

This unauthenticated remote code execution vulnerability in Zoho ManageEngine ADAudit Plus impacts the agent API, suggesting potential responsibility lies with teams managing this application and its endpoints. The first practical step is to identify all ADAudit Plus instances, confirm their network reachability and business criticality, locate the accountable system owner, and then prioritize remediation based on exposure.

  • Own the issue via application or platform teams.
  • Verify ADAudit Plus instances and reachability.
  • Plan phased remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is ManageEngine ADAudit Plus?

ManageEngine ADAudit Plus is a software solution used by organizations to track, monitor, and audit changes within Microsoft Active Directory. It provides visibility into user logins, file modifications, and administrative actions, helping administrators maintain security and compliance across their IT infrastructure.

What does CVE-2026-6516 mean?

This CVE identifies a critical security weakness categorized as CWE-78, or OS Command Injection. In plain terms, it means the software fails to properly filter instructions sent to it, allowing an attacker to run their own commands on the underlying system. Because it is unauthenticated, this happens without the attacker needing a username or password.

How is this vulnerability triggered?

An attacker triggers this bug by sending specially crafted requests to the application's agent API. You do not need to be logged into the system to initiate this. It is important to note that simply having the software installed is not enough to trigger the vulnerability; an attacker must successfully interact with this specific API endpoint to execute their code.

Why does Halo Surface Signal flag this as relevant?

Halo Surface Signal flags this as likely relevant because ADAudit Plus is designed as a centralized service that is often reachable across corporate networks to perform its auditing duties. Because the flaw allows remote code execution without credentials, any instance accessible over a network presents a significant entry point for an attacker to compromise the host system.

What should I do if I use this software?

Your first step is to locate every instance of ADAudit Plus in your environment and identify who is responsible for managing them. Confirm whether these systems are reachable over your network, then work with your team to prioritize applying the vendor's update. Moving quickly to verify your current version number against the vendor's guidance is the most effective way to address the risk.

References