Zoho known exploited vulnerabilities
CISA lists 9 Zoho CVEs as exploited in the wild. 0 were added in the last 12 months (latest 2023-03-07), and 2 are known to be used in ransomware campaigns.
Year = when CISA added the CVE to the catalog (KEV started in November 2021).
Patch first: highest EPSS right now
EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.
- CVE-2020-10189 (ManageEngine): EPSS 99.9%, added 2021-11-03
- CVE-2022-35405 (ManageEngine): EPSS 99.9%, added 2022-09-22
- CVE-2021-44515 (Desktop Central): EPSS 99.9%, added 2021-12-10
- CVE-2021-37415 (ManageEngine ServiceDesk Plus (SDP)): EPSS 99.8%, added 2021-12-01
- CVE-2022-47966 (ManageEngine): EPSS 99.8%, added 2023-01-23
Most affected Zoho products
ManageEngine (6), Desktop Central (1), ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus (1), ManageEngine ServiceDesk Plus (SDP) (1).
All Zoho CVEs in KEV
| CVE | Product | Flaw | Added | Federal due | EPSS | Ransomware |
|---|---|---|---|---|---|---|
| CVE-2022-28810 | ManageEngine | ManageEngine ADSelfService Plus Remote Code Execution | 2023-03-07 | 2023-03-28 | 71.0% | – |
| CVE-2022-47966 | ManageEngine | ManageEngine Multiple Products Remote Code Execution | 2023-01-23 | 2023-02-13 | 99.8% | Yes |
| CVE-2022-35405 | ManageEngine | ManageEngine Multiple Products Remote Code Execution | 2022-09-22 | 2022-10-13 | 99.9% | – |
| CVE-2021-44515 | Desktop Central | Desktop Central Authentication Bypass | 2021-12-10 | 2021-12-24 | 99.9% | – |
| CVE-2021-44077 | ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | ManageEngine ServiceDesk Plus Remote Code Execution | 2021-12-01 | 2021-12-15 | 93.3% | – |
| CVE-2021-37415 | ManageEngine ServiceDesk Plus (SDP) | ManageEngine ServiceDesk Authentication Bypass | 2021-12-01 | 2021-12-15 | 99.8% | – |
| CVE-2021-40539 | ManageEngine | ManageEngine ADSelfService Plus Authentication Bypass | 2021-11-03 | 2021-11-17 | 99.0% | Yes |
| CVE-2020-10189 | ManageEngine | ManageEngine Desktop Central File Upload | 2021-11-03 | 2022-05-03 | 99.9% | – |
| CVE-2019-8394 | ManageEngine | ManageEngine ServiceDesk Plus (SDP) File Upload | 2021-11-03 | 2022-05-03 | 63.3% | – |
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.
Read next: Which CVEs to patch first this week · All vendors