← Vulnerability feed

Vulnerability record · CVE-2022-28219 · published 5 April 2022

CVE-2022-28219: Zoho ManageEngine ADAudit Plus unauthenticated XXE leading to RCE

Zohocorp · Manageengine Adaudit Plus

Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XML external entity (XXE) attack that leads to remote code execution. Because the flaw is reachable without credentials and yields full code execution, it is a severe risk for any internet-exposed or network-reachable ADAudit Plus instance.

9.8 CVSS 3.1 Critical EPSS 97% · top 0.1% CWE-611 · XML external entity (XXE)
9.8CVSS 3.1 base score, v2 7.5
97%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable XXE leading to remote code execution with a CVSS score of 9.8 and very high EPSS probability.

What it is

Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XML external entity (XXE) attack that leads to remote code execution. Because the flaw is reachable without credentials and yields full code execution, it is a severe risk for any internet-exposed or network-reachable ADAudit Plus instance.

Impact

An unauthenticated attacker can execute arbitrary code on the ADAudit Plus server, gaining full control of the host and any data or credentials it processes.

Attack surface

Reachable over the network via the Cewolf XML handling component, with no authentication and no user interaction required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.97193 probability, 99.891 percentile) and public exploit write-ups exist in the references, indicating active interest and likely weaponization.

What to do

  • Upgrade Zoho ManageEngine ADAudit Plus to version 7060 or later, per the vendor patch advisory.
  • If immediate patching is not possible, restrict network access to the ADAudit Plus web interface to trusted management networks only.
  • Disable or block external entity resolution in the underlying XML parser where configuration allows.
  • Monitor vendor advisories and apply any follow-up hotfixes for the Cewolf component.

Detection

  • Inspect web and application logs for XML requests containing DOCTYPE or ENTITY declarations targeting ADAudit Plus endpoints.
  • Alert on unexpected outbound connections or file reads from the ADAudit Plus server process.
  • Monitor for child processes spawned by the ADAudit Plus service that are not part of normal operation.
  • Review network traffic to the ADAudit Plus interface from untrusted or external sources.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-28219 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-47966Zoho ManageEngine on-premise products RCE via SAML SSO and xmlsecMultiple Zoho ManageEngine on-premise products use Apache Santuario xmlsec 1.4.1, whose XSLT features by design leave certain security protections to…KEVEPSS 100%analysed9.8CVE-2023-48792Zohocorp manageengine adaudit plus sql injection vulnerabilityZoho ManageEngine ADAudit Plus through 7250 is vulnerable to SQL Injection in the report export option.EPSS 7.0%9.8CVE-2023-48793Zohocorp manageengine adaudit plus sql injection vulnerabilityZoho ManageEngine ADAudit Plus through 7250 allows SQL Injection in the aggregate report feature.EPSS 7.0%9.8CVE-2021-42847ManageEngine ADAudit Plus arbitrary file write and executionZoho ManageEngine ADAudit Plus before build 7006 permits attackers to write arbitrary files and then execute them. The flaw is remotely reachable wit…EPSS 70%analysed9.8CVE-2020-24786Zohocorp manageengine adselfservice plus improper authentication vulnerabilityAn issue was discovered in Zoho ManageEngine Exchange Reporter Plus before build number 5510, AD360 before build number 4228, ADSelfService Plus befo…EPSS 13%9.8CVE-2020-11532ManageEngine DataSecurity Plus default admin credentials allow auth bypassZoho ManageEngine DataSecurity Plus before 6.0.1 ships with default admin credentials used to communicate with a DataEngine Xnode server. An attacker…EPSS 77%analysed9.8CVE-2018-10466Zohocorp manageengine adaudit plus sql injection vulnerabilityZoho ManageEngine ADAudit Plus before 5.0.0 build 5100 allows blind SQL Injection.EPSS 17%8.8CVE-2024-49574Zohocorp manageengine adaudit plus sql injection vulnerabilityZohocorp ManageEngine ADAudit Plus versions below 8123 are vulnerable to SQL Injection in the reports module.EPSS 3.6%

Source: NIST National Vulnerability Database (record CVE-2022-28219), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.