CVE-2026-5785Disclosure

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Zohocorp ManageEngine PAM360 versions before 8531 and ManageEngine Password Manager Pro versions from 8600 to 13230 are vulnerable to Authenticated SQL injection in the query report module.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-04-17); latest day: 1
  • 5 total mentions across 4 days

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-04-16: 1Mentions · 2026-04-17: 2Mentions · 2026-04-22: 1Mentions · 2026-04-27: 1Patch / Workaround · 2026-04-27: 1Technical Details · 2026-04-16: 1Technical Details · 2026-04-17: 2Technical Details · 2026-04-27: 104-1604-1704-2204-27
Signal classification3 categories
Disclosure
360.0%
General
120.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-161
Disclosure1
2026-04-172
Disclosure2
2026-04-221
General1
2026-04-271
Patch1
Full discourse5 posts
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos ManageEngine ❗ CVE-2026-5785 ❗ CVE-2026-3324 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-manageengine/ https://t.co/42sQFOFxw4

    Post summary

    A brief alert that ManageEngine products have vulnerabilities (CVE-2026-5785 and CVE-2026-3324) with links for further information.

    00001193
    6.7K followersView on X
  • Giuseppe Paternicola@giuseppe_1337
    Patch

    🚨 HIGH Severity Alert CVE-2026-5785 | CVSS 8.1 Authenticated SQL Injection in Zohocorp ManageEngine PAM360 (<8531) & Password Manager Pro (8600-13230) Query report module vulnerable. Patch immediately. #CVE #Vulnerability #PatchNow #ThreatIntel https://t.co/6AbmxBfVnk

    Post summary

    The post announces an authenticated SQL injection vulnerability (CVE-2026-5785) in Zohocorp ManageEngine PAM360 and Password Manager Pro, urging users to apply the patch immediately.

    0000041
    27 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-5785 Zohocorp ManageEngine PAM360 versions before 8531 and ManageEngine Password Manager Pro versions from 8600 to 13230 are vulnerable to Authenticated SQL injection in the… https://www.cve.org/CVERecord?id=CVE-2026-5785 ----- Traducción: CVE-2026-5785 Zoh… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-5785, specifying affected ManageEngine PAM360 and Password Manager Pro versions and noting an authenticated SQL injection vulnerability, but does not mention a PoC, exploit, patch, or evidence of active exploitation.

    0000023
    71 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5785 Zohocorp ManageEngine PAM360 versions before 8531 and ManageEngine Password Manager Pro versions from 8600 to 13230 are vulnerable to Authenticated SQL injection in the… https://www.cve.org/CVERecord?id=CVE-2026-5785

    Post summary

    CVE-2026-5785 exposes a vulnerability in ManageEngine PAM360 and Password Manager Pro, allowing authenticated SQL injection for the specified versions. No exploit, patch, or active exploitation details are provided.

    0000086
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5785 Authenticated SQL Injection in ManageEngine PAM360 and Password Manager Pro https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5785

    Post summary

    The post flags a newly disclosed authenticated SQL injection vulnerability in ManageEngine products, but offers no PoC, exploit code, or mention of active exploitation.

    0000049
    4.0K followersView on X

Explore more