← Vulnerability feed

Vulnerability record · CVE-2022-47966 · published 18 January 2023

CVE-2022-47966: Zoho ManageEngine on-premise products RCE via SAML SSO and xmlsec

Zohocorp · Manageengine Access Manager Plus

Multiple Zoho ManageEngine on-premise products use Apache Santuario xmlsec 1.4.1, whose XSLT features by design leave certain security protections to the application; ManageEngine did not implement them, allowing remote code execution. The flaw affects a long list of products and is only reachable when SAML SSO has ever been configured, or in some products is currently active. It matters because it is unauthenticated, network-reachable, and rated critical.

9.8 CVSS 3.1 Critical CISA KEV since 23 Jan 2023 Known ransomware use EPSS 100% · top 0.1% CWE-20 · Improper input validation
9.8CVSS 3.1 base score
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
22Affected product versions listed by NVD
21References, 12 tagged exploit
31 Jul 2026Last modified by NVD

Description

Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections, and the ManageEngine applications did not provide those protections. This affects Access Manager Plus before 4308, Active Directory 360 before 4310, ADAudit Plus before 7081, ADManager Plus before 7162, ADSelfService Plus before 6211, Analytics Plus before 5150, Application Control Plus before 10.1.2220.18, Asset Explorer before 6983, Browser Security Plus before 11.1.2238.6, Device Control Plus before 10.1.2220.18, Endpoint Central before 10.1.2228.11, Endpoint Central MSP before 10.1.2228.11, Endpoint DLP before 10.1.2137.6, Key Manager Plus before 6401, OS Deployer before 1.1.2243.1, PAM 360 before 5713, Password Manager Pro before 12124, Patch Manager Plus before 10.1.2220.18, Remote Access Plus before 10.1.2228.11, Remote Monitoring and Management (RMM) before 10.1.41. ServiceDesk Plus before 14004, ServiceDesk Plus MSP before 13001, SupportCenter Plus before 11026, and Vulnerability Manager Plus before 10.1.2220.18. Exploitation is only possible if SAML SSO has ever been configured for a product (for some products, exploitation requires that SAML SSO is currently active).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated network RCE with a 9.8 CVSS score, KEV listing with known ransomware use, and near-maximum EPSS probability.

What it is

Multiple Zoho ManageEngine on-premise products use Apache Santuario xmlsec 1.4.1, whose XSLT features by design leave certain security protections to the application; ManageEngine did not implement them, allowing remote code execution. The flaw affects a long list of products and is only reachable when SAML SSO has ever been configured, or in some products is currently active. It matters because it is unauthenticated, network-reachable, and rated critical.

Impact

An unauthenticated attacker can execute arbitrary code on the affected ManageEngine server, gaining full control of that host and any credentials or managed endpoints it administers.

Attack surface

Reached over the network via the SAML SSO handling path; the CVSS vector shows no privileges and no user interaction required. Exploitation is conditional: SAML SSO must have been configured at some point, and for some products must be currently active.

Exploitation

CISA added it to KEV on 2023-01-23 with a 2023-02-13 due date and flags known ransomware campaign use; EPSS 30-day probability is 0.99753 (99.954th percentile) and multiple references are tagged Exploit.

What to do

  • Apply the vendor updates listed in the ManageEngine advisory for each affected product (for example ServiceDesk Plus 14004, ADSelfService Plus 6211, Endpoint Central 10.1.2228.11, Password Manager Pro 12124).
  • If a product cannot be patched immediately, disable or remove SAML SSO configuration where operationally possible, since exploitation depends on it.
  • Restrict network access to ManageEngine web interfaces to trusted management networks rather than exposing them to the internet.
  • Inventory all on-premise ManageEngine instances and versions to confirm which are affected and which have SAML SSO configured.
  • Monitor vendor and CISA guidance for follow-up advisories, as this CVE is tied to a broader CISA advisory (aa23-250a).

Detection

  • Review ManageEngine web server and application logs for anomalous SAML responses or requests to SSO endpoints, especially from unexpected source addresses.
  • Hunt for unexpected child processes spawned by ManageEngine Java service processes, which would indicate post-exploitation code execution.
  • Search for outbound connections or new files/webshells on ManageEngine hosts that do not match normal administrative activity.
  • Correlate with KEV/EPSS-driven alerting and check whether any affected instance still has SAML SSO enabled.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2022-47966 to the Known Exploited Vulnerabilities catalog on 23 January 2023 as "Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 13 February 2023.

Affected products

22 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/170882/Zoho-ManageEngine-ServiceDesk-Plus-14003-Remote-Code-Execution.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/170925/ManageEngine-ADSelfService-Plus-Unauthenticated-SAML-Remote-Code-Execution.h ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/170943/Zoho-ManageEngine-Endpoint-Central-MSP-10.1.2228.10-Remote-Code-Execution.ht ExploitThird Party AdvisoryVDB Entry
https://attackerkb.com/topics/gvs0Gv8BID/cve-2022-47966/rapid7-analysis ExploitThird Party Advisory
https://blog.viettelcybersecurity.com/saml-show-stopper/ ExploitThird Party Advisory
https://github.com/apache/santuario-xml-security-java/tags?after=1.4.6 Release Notes
https://github.com/horizon3ai/CVE-2022-47966 Third Party Advisory
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-250a Third Party AdvisoryUS Government Resource
https://www.horizon3.ai/manageengine-cve-2022-47966-technical-deep-dive/ ExploitThird Party Advisory
https://www.manageengine.com/security/advisory/CVE/cve-2022-47966.html PatchVendor Advisory
http://packetstormsecurity.com/files/170882/Zoho-ManageEngine-ServiceDesk-Plus-14003-Remote-Code-Execution.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/170925/ManageEngine-ADSelfService-Plus-Unauthenticated-SAML-Remote-Code-Execution.h ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/170943/Zoho-ManageEngine-Endpoint-Central-MSP-10.1.2228.10-Remote-Code-Execution.ht ExploitThird Party AdvisoryVDB Entry
https://attackerkb.com/topics/gvs0Gv8BID/cve-2022-47966/rapid7-analysis ExploitThird Party Advisory
https://blog.viettelcybersecurity.com/saml-show-stopper/ ExploitThird Party Advisory
https://github.com/apache/santuario-xml-security-java/tags?after=1.4.6 Release Notes
https://github.com/horizon3ai/CVE-2022-47966 Third Party Advisory
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-250a Third Party AdvisoryUS Government Resource
https://www.horizon3.ai/manageengine-cve-2022-47966-technical-deep-dive/ ExploitThird Party Advisory
https://www.manageengine.com/security/advisory/CVE/cve-2022-47966.html PatchVendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-47966 US Government Resource

Track CVE-2022-47966 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-35405Zoho ManageEngine Password Manager Pro unauthenticated deserialization RCEZoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution via deserializatio…KEVEPSS 100%analysed9.8CVE-2021-40539Zoho ManageEngine ADSelfService Plus REST API auth bypass to RCEZoho ManageEngine ADSelfService Plus version 6113 and prior contains an authentication bypass in its REST API that leads to remote code execution. Be…KEVEPSS 99%analysed6.8CVE-2022-28810Zoho ManageEngine ADSelfService Plus OS command injection via custom scriptZoho ManageEngine ADSelfService Plus before build 6122 lets a remote authenticated administrator run arbitrary OS commands as SYSTEM through the poli…KEVEPSS 71%analysed10.0CVE-2019-3905Zohocorp manageengine adselfservice plus server-side request forgery (ssrf) vulnerabilityZoho ManageEngine ADSelfService Plus 5.x before build 5703 has SSRF.EPSS 3.3%9.8CVE-2023-48792Zohocorp manageengine adaudit plus sql injection vulnerabilityZoho ManageEngine ADAudit Plus through 7250 is vulnerable to SQL Injection in the report export option.EPSS 7.0%9.8CVE-2023-48793Zohocorp manageengine adaudit plus sql injection vulnerabilityZoho ManageEngine ADAudit Plus through 7250 allows SQL Injection in the aggregate report feature.EPSS 7.0%9.8CVE-2023-35854Zohocorp manageengine adselfservice plus missing authentication for critical function vulnerabilityZoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain controller session token for…EPSS 6.0%9.8CVE-2022-47523Zoho ManageEngine PAM products SQL injectionZoho ManageEngine Access Manager Plus, Password Manager Pro and PAM360 contain a SQL injection flaw fixed in versions 4309, 12210 and 5801 respective…EPSS 71%analysed

Source: NIST National Vulnerability Database (record CVE-2022-47966), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.