CISA Known Exploited Vulnerability

CVE-2022-47966 Ransomware

Zoho · ManageEngine

Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability

Date added
BOD 22-01 due date
CWE
Ransomware Known

CISA description

Multiple Zoho ManageEngine products contain an unauthenticated remote code execution vulnerability due to the usage of an outdated third-party dependency, Apache Santuario.

Required action

Apply updates per vendor instructions.