CVE-2026-74849

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to a remote code execution vulnerability in the GINA client.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 2 mentions (2026-09-22); latest day: 2
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-09-22: 2Mentions · 2026-09-23: 209-2209-23
Referenced assets4 URLs
Full discourse4 posts
  • CERT-PY@CERTpy

    ⚠️ Vulnerabilidades en productos ManageEngine ❗ CVE-2026-75791 ❗ CVE-2026-74849 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-manageengine-2/ https://t.co/usol6bFBRZ

    01030222
    6.7K followersView on X
  • The Daily Tech Feed@dailytechonx

    A severe RCE flaw in ManageEngine ADSelfService Plus (CVE-2026-74849) lets attackers execute code as SYSTEM straight from the Windows login screen — no credentials needed. This bug targets the GINA client in builds 7000 and earlier; a patch arrived in build 7001. If you manage ADSelfService Plus, update now, audit login-screen activity, and lock down exposure to mitigate risk. #ManageEngine #Cybersecurity #ADSelfService #RCE #WindowsSecurity #Vulnerability https://thedailytechfeed.com/critical-adselfservice-plus-bug-lets-hackers-elevate-to-system-via-windows-login/

    0000029
    737 followersView on X
  • NEXSIGHT@NEXSIGHTNEWS

    ManageEngine ADSelfService PlusのGINAクライアントにSYSTEM権限を奪われるRCE脆弱性「CVE-2026-74849」、ビルド7001で修正 https://cyber.nexsight.co/articles/2026/09/23/manageengine-adselfservice-plus-cve-2026-74849-gina-rce-2026-09-23/

    0000047
    71 followersView on X
  • Daily CyberSecurity@Daily_CyberSec

    A critical ManageEngine ADSelfService Plus vulnerability (CVE-2026-74849) allows system compromise. Update to build 7001 to secure your endpoints. #ManageEngine #ADSelfServicePlus #CVE202674849 #Cybersecurity #Infosec #RCE https://securityonline.info/manageengine-adselfservice-plus-vulnerability-cve-2026-74849/

    00000347
    13.0K followersView on X

Explore more