ManageEngine AD360 Integrated Products Hit by Account Takeover ...
ManageEngine disclosed a critical vulnerability, CVE-2026-11374, in its AD360 suite affecting products like ADSelfService Plus and M365 Manager Plus. The flaw, due to predictable SSO ticket generatio...n, allows unauthorized access. ManageEngine has issued updates to fix the issue, urging immediate patching to prevent potential account takeovers.
ManageEngine has patched a critical security vulnerability, CVE-2026-11374, in its identity and access management solutions integrated with AD360. This flaw allowed unauthorized prediction of SSO tok...ens, risking account takeovers. Affected products include ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus. Organizations are urged to apply the latest patches to secure their systems.
A critical vulnerability (CVE-2026-11374) was identified in ManageEngine's AD360, affecting ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus. The flaw allows an attacker ...to predict SSO tickets, leading to potential account takeover. Users are advised to update to the latest software versions to mitigate risks.
Predictable SSO Tickets in ManageEngine AD360-Integrated Products
A critical vulnerability, CVE-2026-11374, has been identified in ManageEngine products integrated with AD360. This flaw allows unauthenticated attackers to predict SSO tickets, leading to unauthorize...d access and potential account takeover. Zoho Corporation has released patches to address this issue by enhancing the SSO ticket generation mechanism.
Ad360 introduces a new optimization algorithm for real-time bidding in advertising campaigns. This algorithm enhances KPI maximization by configuring and competing advertising channels effectively.
ManageEngine Enhances AD360 With Risk Exposure Management and Local User MFA To Strengthen Identity Threat Defences
ManageEngine, a division of Zoho Corporation, has enhanced its AD360 identity and access management platform with new features for risk exposure management and local user multi-factor authentication ...(MFA). These updates aim to bolster identity threat defenses by enabling security teams to detect privilege escalation risks and secure unmanaged local accounts. The enhancements align with various compliance standards and aim to transform identity management into an active security control.