CyberMax
Home › Exploited CVEs

Zoho known exploited vulnerabilities

CISA KEV catalog 2026.09.25 (1,726 CVEs) with FIRST EPSS scores from 2026-09-27.

CISA lists 9 Zoho CVEs as exploited in the wild. 0 were added in the last 12 months (latest 2023-03-07), and 2 are known to be used in ransomware campaigns.

Zoho CVEs added to CISA KEV per year
2021: 6202162022: 1202212023: 220232

Year = when CISA added the CVE to the catalog (KEV started in November 2021).

Patch first: highest EPSS right now

EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.

Most affected Zoho products

ManageEngine (6), Desktop Central (1), ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus (1), ManageEngine ServiceDesk Plus (SDP) (1).

All Zoho CVEs in KEV

CVEProductFlawAddedFederal dueEPSSRansomware
CVE-2022-28810ManageEngineManageEngine ADSelfService Plus Remote Code Execution2023-03-072023-03-2871.0%–
CVE-2022-47966ManageEngineManageEngine Multiple Products Remote Code Execution2023-01-232023-02-1399.8%Yes
CVE-2022-35405ManageEngineManageEngine Multiple Products Remote Code Execution2022-09-222022-10-1399.9%–
CVE-2021-44515Desktop CentralDesktop Central Authentication Bypass2021-12-102021-12-2499.9%–
CVE-2021-44077ManageEngine ServiceDesk Plus (SDP) / SupportCenter PlusManageEngine ServiceDesk Plus Remote Code Execution2021-12-012021-12-1593.3%–
CVE-2021-37415ManageEngine ServiceDesk Plus (SDP)ManageEngine ServiceDesk Authentication Bypass2021-12-012021-12-1599.8%–
CVE-2021-40539ManageEngineManageEngine ADSelfService Plus Authentication Bypass2021-11-032021-11-1799.0%Yes
CVE-2020-10189ManageEngineManageEngine Desktop Central File Upload2021-11-032022-05-0399.9%–
CVE-2019-8394ManageEngineManageEngine ServiceDesk Plus (SDP) File Upload2021-11-032022-05-0363.3%–
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

Read next: Which CVEs to patch first this week · All vendors