CVE-2020-10189Active Exploitation(zohocorp / manageengine_desktop_central)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch zohocorp manageengine_desktop_central systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is related to the CewolfServlet and MDMLogUploaderServlet servlets.

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-05-03. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-502

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • manageengine_desktop_central

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Peaked 3d ago at 1 mentions (2026-03-30); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
manageengine_desktop_central

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-03-30: 1Mentions · 2026-03-31: 1Mentions · 2026-04-06: 1Mentions · 2026-10-01: 1Active Exploitation · 2026-03-30: 1Active Exploitation · 2026-03-31: 1Patch / Workaround · 2026-04-06: 1Technical Details · 2026-03-30: 1Technical Details · 2026-03-31: 103-3003-3104-0610-01
Signal classification2 categories
Active Exploitation
266.7%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-301
Active Exploitation1
2026-03-311
Active Exploitation1
2026-04-061
Patch1
Full discourse4 posts
  • Patrick Roland@DeusLogica
    Patch

    🚨 CISA KEV Update | CRITICAL CISA just batched multiple Zoho ManageEngine vulnerabilities into the KEV (including CVE-2021-40539 & CVE-2020-10189). These are classic APT initial access vectors for DIB perimeters. If you're an MSSP managing Zoho for defense contractors, check your patch delta immediately. Don't wait for the compliance deadline. Source: CISA / Roland Fleet CTI #CMMC #MSSP #CVE #KEV

    Post summary

    The post announces a CISA KEV update for specific Zoho ManageEngine CVEs and urges MSSPs to immediately apply patches, with no mention of PoCs or active exploitation.

    01000137
    314 followersView on X
  • Patrick Roland@DeusLogica
    Active Exploitation

    ⚠️ CISA KEV UPDATE | high confidence CVE-2020-10189 added to CISA KEV Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage component. ACTIVE EXPLOITATION CONFIRMED ATT&CK: Exploit Public-Facing Application (T1190) Source: CISA KEV | Reliability: A Link: https://nvd.nist.gov/vuln/detail/CVE-2020-10189 #CVE #CISA #KEV #threatintel #infosec

    Post summary

    CISA has confirmed that CVE‑2020‑10189 is actively exploited in the wild, enabling remote code execution via deserialization in Zoho ManageEngine Desktop Central before version 10.0.474.

    1000036
    311 followersView on X
  • ♫Why♥Not♪@Python_s_

    #NØØT Security Alerts Classification: High CVE: CVE-2020-10189 Product: Zoho / ManageEngine Summary: VulnCheck reports real-world exploitation activity affecting Zoho / ManageEngine. Evidence: Public PoC/exploit available; Active exploitation reported; Severe impact class; Live exploitation observed by VulnCheck canaries Impact: The vulnerability has a severe impact class such as code execution, authentication bypass, account takeover, or privilege escalation. Action: Prioritize vendor remediation, identify exposed affected systems, and investigate for evidence of exploitation when applicable. Date: 25 Mar 2020 Source: https://vulncheck.com/xdb/5eb1a844d5f5 #NØØT #CyberSecurity #InfoSec #ThreatIntelligence #CyberThreats #CVE #CyberDefense #Zoho #ManageEngine #CVE_2020_10189 #ActiveExploitation #Exploit

    0000037
    226 followersView on X
  • Patrick Roland@DeusLogica
    Active Exploitation

    ⚠️ CISA KEV UPDATE | high confidence CVE-2020-10189 added to CISA KEV Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage ACTIVE EXPLOITATION CONFIRMED ATT&CK: Exploit Public-Facing Application (T1190) Source: CISA KEV | Reliability: A Link: https://nvd.nist.gov/vuln/detail/CVE-2020-10189 #CVE #CISA #KEV #threatintel #infosec

    Post summary

    The notice announces that CVE-2020-10189 has been added to the CISA KEV list and confirms active exploitation of remote code execution in Zoho ManageEngine Desktop Central, with no mitigation or patch details provided.

    0000038
    306 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appzohocorpmanageengine_desktop_central---

Explore more