CVE-2019-8394Active Exploitation(zohocorp / manageengine_servicedesk_plus)

LOWCVSS 6.5 · MEDIUMCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for zohocorp manageengine_servicedesk_plus systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization.

3.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-05-03. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • manageengine_servicedesk_plus

Threat summary

  • Active exploitation appears in 2 classified signals
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Technical details provided in 2 signals
  • Peaked 1d ago at 1 mentions (2026-03-30); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
manageengine_servicedesk_plus

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-30: 1Mentions · 2026-03-31: 1Active Exploitation · 2026-03-30: 1Active Exploitation · 2026-03-31: 1Technical Details · 2026-03-30: 1Technical Details · 2026-03-31: 103-3003-31
Signal classification1 categories
Active Exploitation
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Patrick Roland@DeusLogica
    Active Exploitation

    ⚠️ CISA KEV UPDATE | high confidence CVE-2019-8394 added to CISA KEV Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization. ACTIVE EXPLOITATION CONFIRMED ATT&CK: Exploit Public-Facing Application (T1190) Source: CISA KEV | Reliability: A Link: https://nvd.nist.gov/vuln/detail/CVE-2019-8394 #CVE #CISA #KEV #threatintel #infosec

    Post summary

    The CISA KEV update confirms CVE-2019-8394 is actively exploited, affecting Zoho ManageEngine ServiceDesk Plus prior to version 10.0 build 10012 through a remote file upload vulnerability via the login‑page customization feature.

    1000051
    311 followersView on X
  • Patrick Roland@DeusLogica
    Active Exploitation

    ⚠️ CISA KEV UPDATE | high confidence CVE-2019-8394 added to CISA KEV Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization. ACTIVE EXPLOITATION CONFIRMED ATT&CK: Exploit Public-Facing Application (T1190) Source: CISA KEV | Reliability: A Link: https://nvd.nist.gov/vuln/detail/CVE-2019-8394 #CVE #CISA #KEV #threatintel #infosec

    Post summary

    The post confirms that CVE-2019-8394 is actively exploited, affecting pre‑10.0 builds of Zoho ManageEngine ServiceDesk Plus by enabling remote file uploads, with no PoC or exploit code shared.

    0000040
    306 followersView on X
CPE platform detail14 entries

14 of 14 entries

PartVendorProductVersionTarget SWTarget HW
Appzohocorpmanageengine_servicedesk_plus---
Appzohocorpmanageengine_servicedesk_plus10.0.0--
Appzohocorpmanageengine_servicedesk_plus10.0.0--
Appzohocorpmanageengine_servicedesk_plus10.0.0--
Appzohocorpmanageengine_servicedesk_plus10.0.0--
Appzohocorpmanageengine_servicedesk_plus10.0.0--
Appzohocorpmanageengine_servicedesk_plus10.0.0--
Appzohocorpmanageengine_servicedesk_plus10.0.0--
Appzohocorpmanageengine_servicedesk_plus10.0.0--
Appzohocorpmanageengine_servicedesk_plus10.0.0--
Appzohocorpmanageengine_servicedesk_plus10.0.0--
Appzohocorpmanageengine_servicedesk_plus10.0.0--
Appzohocorpmanageengine_servicedesk_plus10.0.0--
Appzohocorpmanageengine_servicedesk_plus10.0.0--

Explore more