CVE-2026-2740: Remote Code Execution
Zohocorp ManageEngine ADSelfService Plus version before 6525, DataSecurity Plus before 6264 and RecoveryManager Plus before 6313 are vulnerable to Authenticated Remote code execution in the agent machines due to the bug in the 3rd party dependency.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ManageEngine ADSelfService Plusto a version that resolves this vulnerability.Fixed in 6525 - Upgrade
Upgrade
ManageEngine DataSecurity Plusto a version that resolves this vulnerability.Fixed in 6264 - Upgrade
Upgrade
ManageEngine RecoveryManager Plusto a version that resolves this vulnerability.Fixed in 6313
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2740?
CVE-2026-2740 has a high severity rating of 8.4.
What is the risk associated with CVE-2026-2740?
CVE-2026-2740 has a risk rating of 69, indicating a significant threat level.
How do I fix CVE-2026-2740?
To fix CVE-2026-2740, you should update to Zoho ManageEngine ADSelfService Plus version 6525 or later, DataSecurity Plus version 6264 or later, and RecoveryManager Plus version 6313 or later.
What type of vulnerability is CVE-2026-2740?
CVE-2026-2740 is categorized as a Command Injection vulnerability leading to Authenticated Remote Code Execution.
Who is affected by CVE-2026-2740?
CVE-2026-2740 affects users of Zoho ManageEngine ADSelfService Plus, DataSecurity Plus, and RecoveryManager Plus prior to the specified versions.