Vulnerability record · CVE-2022-28219 · published 5 April 2022
CVE-2022-28219: Zoho ManageEngine ADAudit Plus unauthenticated XXE leading to RCE
Zohocorp · Manageengine Adaudit Plus
Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XML external entity (XXE) attack that leads to remote code execution. Because the flaw is reachable without credentials and yields full code execution, it is a severe risk for any internet-exposed or network-reachable ADAudit Plus instance.
Description
Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable XXE leading to remote code execution with a CVSS score of 9.8 and very high EPSS probability.
What it is
Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XML external entity (XXE) attack that leads to remote code execution. Because the flaw is reachable without credentials and yields full code execution, it is a severe risk for any internet-exposed or network-reachable ADAudit Plus instance.
Impact
An unauthenticated attacker can execute arbitrary code on the ADAudit Plus server, gaining full control of the host and any data or credentials it processes.
Attack surface
Reachable over the network via the Cewolf XML handling component, with no authentication and no user interaction required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.97193 probability, 99.891 percentile) and public exploit write-ups exist in the references, indicating active interest and likely weaponization.
What to do
- Upgrade Zoho ManageEngine ADAudit Plus to version 7060 or later, per the vendor patch advisory.
- If immediate patching is not possible, restrict network access to the ADAudit Plus web interface to trusted management networks only.
- Disable or block external entity resolution in the underlying XML parser where configuration allows.
- Monitor vendor advisories and apply any follow-up hotfixes for the Cewolf component.
Detection
- Inspect web and application logs for XML requests containing DOCTYPE or ENTITY declarations targeting ADAudit Plus endpoints.
- Alert on unexpected outbound connections or file reads from the ADAudit Plus server process.
- Monitor for child processes spawned by the ADAudit Plus service that are not part of normal operation.
- Review network traffic to the ADAudit Plus interface from untrusted or external sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://cewolf.sourceforge.net/new/index.html | ProductThird Party Advisory |
| http://packetstormsecurity.com/files/167997/ManageEngine-ADAudit-Plus-Path-Traversal-XML-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| https://manageengine.com | Vendor Advisory |
| https://www.horizon3.ai/red-team-blog-cve-2022-28219/ | ExploitThird Party Advisory |
| https://www.manageengine.com/products/active-directory-audit/cve-2022-28219.html | PatchVendor Advisory |
| http://cewolf.sourceforge.net/new/index.html | ProductThird Party Advisory |
| http://packetstormsecurity.com/files/167997/ManageEngine-ADAudit-Plus-Path-Traversal-XML-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| https://manageengine.com | Vendor Advisory |
| https://www.horizon3.ai/red-team-blog-cve-2022-28219/ | ExploitThird Party Advisory |
| https://www.manageengine.com/products/active-directory-audit/cve-2022-28219.html | PatchVendor Advisory |
Track CVE-2022-28219 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-28219), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.