CVE-2026-11374Disclosure

MEDIUMCVSS 9.0 · CRITICAL

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by an unauthenticated user, leading to account takeover.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-330CWE-340

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 13 mentions across 9 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 8 signals
  • Disclosure: 6 classified signals
  • Peaked 6d ago at 4 mentions (2026-06-25); latest day: 1
  • 13 total mentions across 9 days

Deep dive

Activity timeline13 mentions / 9d
01234Mentions · 2026-06-23: 1Mentions · 2026-06-24: 2Mentions · 2026-06-25: 4Mentions · 2026-06-26: 1Mentions · 2026-07-02: 1Mentions · 2026-07-08: 1Mentions · 2026-07-22: 1Mentions · 2026-07-28: 1Mentions · 2026-07-30: 1Active Exploitation · 2026-06-24: 1Active Exploitation · 2026-07-22: 1Patch / Workaround · 2026-06-23: 1Patch / Workaround · 2026-06-24: 1Patch / Workaround · 2026-06-25: 2Patch / Workaround · 2026-07-02: 1Technical Details · 2026-06-23: 1Technical Details · 2026-06-24: 1Technical Details · 2026-06-25: 3Technical Details · 2026-06-26: 1Technical Details · 2026-07-02: 1Technical Details · 2026-07-22: 106-2306-2406-2506-2607-0207-0807-2207-2807-30
Signal classification4 categories
Disclosure
646.2%
Patch
323.1%
Active Exploitation
215.4%
General
215.4%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-06-231
Disclosure1
2026-06-242
Active Exploitation1Patch1
2026-06-254
Disclosure3Patch1
2026-06-261
Disclosure1
2026-07-021
Patch1
2026-07-081
General1
2026-07-221
Active Exploitation1
2026-07-281
General1
2026-07-301
Disclosure1
Full discourse13 posts
  • ボス@サイバーセキュリティの専門家@boss_sec_labo
    Patch

    通信・開発・認証。企業ITを支える三本柱に、今日三本同時に穴が空いた。 CiscoのSSRF脆弱性、CI/CDの設計欠陥、ManageEngineのSSO認証回避。 「まさかそこが」という場所から攻撃者は入ってくる。そこが狙い目だからだ。 ・CiscoUCM CVE-2026-20230、SSRFでWebシェル投下・root権限奪取 ・「Cordyceps」CI/CD脆弱性、GitHub上3万超リポジトリで無認証コード改ざん可能 ・ManageEngine CVE-2026-11374、CVSS9.0のSSO認証回避・アカウント乗っ取り パッチは三件全部出ている。問題は適用済みかどうかだ。今すぐ担当者に確認しろ。 「対応中」という返答では終わらせるな。完了期限を日付で取れ。 君の現場で「完了」と言い切れる根拠は何だ?

    Post summary

    The post announces three new high‑severity CVEs—Cisco UCM SSRF (root privilege), a CI/CD design flaw affecting over 30,000 GitHub repos, and a ManageEngine SSO bypass (CVSS 9.0)—and stresses that patches have been released but must be verified as applied.

    04136142.3K
    1.5K followersView on X
  • Daily CyberSecurity@the_yellow_fall
    Disclosure

    A critical ManageEngine account takeover vulnerability (CVE-2026-11374) exposes AD360 integrated deployments to unauthenticated attacks. Update systems now. #ManageEngine #CyberSecurity #Vulnerability #CVE202611374 #InfoSec https://securityonline.info/manageengine-account-takeover-cve-2026-11374 https://t.co/kbYXnt3vo8

    Post summary

    The post announces a critical account‑takeover flaw (CVE‑2026‑11374) in ManageEngine AD360 that permits unauthenticated attacks, urging administrators to update their systems immediately.

    020941.1K
    12.8K followersView on X
  • Bishop Fox@bishopfox
    General

    A critical CVE... A predictable SSO ticket... An account takeover! 🫣 So why isn't this being mass exploited? Our latest research on CVE-2026-11374 breaks down the attack path, why exploitability is limited, and what defenders should do next. https://t.co/8YkPmnhHu9

    Post summary

    The tweet references research into CVE-2026-11374, outlining the attack path and limited exploitability, but offers no PoC, tool, patch, or debunking information.

    11011598
    25.6K followersView on X
  • Eduardo P. Sánchez@darkslaker
    Disclosure

    Not every CVSS 9.0 vulnerability is equally practical to exploit. BishopFox latest research walks through the root cause, attack path, layered defenses, and defender takeaways for CVE-2026-11374. https://bfx.social/4fEiVxD

    Post summary

    BishopFox’s post offers a research walk-through of CVE‑2026‑11374, covering its root cause and defense considerations, but it provides no PoC, exploit code, active exploitation evidence, or patch guidance.

    00010370
    1.1K followersView on X
  • iototsecnews@iototsecnews
    Patch

    ManageEngine AD360 の脆弱性 CVE-2026-11374 が FIX:アイデンティティ/アクセス管理に深刻な影響 https://iototsecnews.jp/2026/06/25/manageengine-ad360-integration-flaw-exposes-user-identity-and-role-information-to-attackers/ 複数の認証管理ソフトを束ねる AD360 統合環境において、利用者を識別するための SSO トークンが推測される弱点 CVE-2026-11374 が見つかりました。この問題により、未認証の攻撃者が有効なセッション・トークンを生成し、ユーザーになりすまして不正アクセスする恐れがあります。ID 情報やロール情報の露出、権限昇格、内部偵察につながる可能性があるため、影響を受ける製品では最新サービスパックの適用と認証ログ監視が重要です。 #CVE202611374 #ManageEngine #Vulnerability

    Post summary

    The report announces a new AD360 SSO token vulnerability (CVE‑2026‑11374), warns of potential session hijacking and data exposure, and advises applying the latest service pack and monitoring logs.

    01000232
    501 followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    『the SSO tickets generated to authenticate that session could be predicted by an unauthenticated attacker,』 CVE-2026-11374: Account takeover vulnerability in ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus https://www.manageengine.com/products/self-service-password/advisory/CVE-2026-11374.html

    Post summary

    CVE-2026-11374 allows unauthenticated attackers to predict SSO tickets, potentially enabling account takeover in ManageEngine products; the text highlights the vulnerability but does not provide PoC, exploit code, or patch details.

    01000444
    6.9K followersView on X
  • Cyber Edition@CyberEdition
    Patch

    🔓 A high-severity flaw (CVE-2026-11374) in ManageEngine AD360 lets unauthenticated attackers predict SSO tickets and hijack user accounts. Affected products include ADSelfService Plus, ADAudit Plus, M365 Manager Plus, and RecoveryManager Plus. Patch now. #CyberSecurity #IAM Read more: https://thecyberedition.com/manageengine-ad360-sso-bug-lets-attackers-hijack-user-accounts/

    Post summary

    A high‑severity flaw (CVE‑2026‑11374) in ManageEngine AD360 allows unauthenticated attackers to predict SSO tickets and hijack accounts; a vendor patch is available.

    0000184
    739 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨Critical - ManageEngine SSO Ticket Prediction Account Takeover (CVE-2026-11374) In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus (when deployed as integrated components within ManageEngine AD360), SSO tickets generated for session authentication could be predicted by an unauthenticated attacker. This allows an attacker to obtain a targeted user's identity and role information, leading to full account takeover and compromise of confidentiality, integrity, and availability across the affected systems. 👉 Upgrade to the fixed versions: ADSelfService Plus 6529+ RecoveryManager Plus 6321+ M365 Manager Plus 4817+ ADAudit Plus 8703+

    Post summary

    This is a disclosure of a critical ManageEngine vulnerability (CVE-2026-11374) that lets unauthenticated attackers predict SSO tickets and take over accounts, accompanied by vendor-released fixed versions.

    00001100
    226 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploited predictable SSO ticket generation in ManageEngine AD360-integrated products to achieve account takeover (CVE-2026-11374). By predicting millisecond timestamps, threat actors gained administrative access and moved laterally within compromised networks. #IdentitySecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/cve-2026-11374-manageengine-sso-auth-bypass

    Post summary

    The tweet reports that CVE‑2026‑11374, a predictable SSO ticket generation flaw in ManageEngine AD360, has been actively exploited by attackers to gain administrative access and lateral movement, with a link to a full analysis.

    0000056
    1.9K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidad en productos Zoho ❗ CVE-2026-11374 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-zoho-2/ https://t.co/Z6JPv28mwH

    Post summary

    The tweet flags CVE-2026-11374 as a vulnerability affecting Zoho products and provides links for more information, but offers no details on the vulnerability itself, exploitation, or mitigation.

    00000230
    6.7K followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    Disclosure

    🚨 ManageEngine AD360 SSO Token Prediction Flaw – #CVE-2026-11374: Critical #Account Takeover Vulnerability Exposes Enterprise Identity Infrastructure + Video https://undercodetesting.com/manageengine-ad360-sso-token-prediction-flaw-cve-2026-11374-critical-account-takeover-vulnerability-exposes-enterprise-identity-infrastructure-video/ Educational Purposes!

    Post summary

    The post announces a critical account takeover flaw in ManageEngine AD360's SSO token prediction, linking to a video presented for educational purposes.

    0000050
    639 followersView on X
  • Cyber Threat Observatory | Alan Turing Institute@TuringCyberObs
    Disclosure

    CVE-2026-11374 ManageEngine Improper authentication could let attackers predict SSO tickets and take over accounts, turning identity tooling into a wider access-control risk Full analysis: https://github.com/alan-turing-institute/cyber-threat-observatory/blob/main/reports/2026-06-23/TIER_2_CVE-2026-11374.md #CyberSecurity #IdentitySecurity #VulnerabilityManagement

    Post summary

    The post announces CVE-2026-11374 affecting ManageEngine, noting that improper authentication allows attackers to predict SSO tickets and hijack accounts, and links to a detailed analysis without providing PoC or exploit code.

    0000054
    55 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    A lot of offensive activities were identified targeting Zoho ManageEngine ADSelfService Plus and other products (CVE-2026-11374) https://vuldb.com/vuln/372876/cti

    Post summary

    The brief CTI notice indicates that offensive actors are actively targeting CVE-2026-11374, but provides no specific exploit details or mitigation guidance.

    00000100
    2.2K followersView on X

Explore more