ManageEngine IAM A.I CyberSecurity Scoring
ManageEngine IAM
Company Information
Website:https://www.manageengine.com/active-directory-360/
Employees number:None
Number of followers:11,342
NAICS:5112
Industry Type:Software Development
Homepage:manageengine.com
ManageEngine IAM Risk Score (AI oriented)
Between 750 and 799
ManageEngine IAMSoftware Development
Updated:
25/06/2026
25/06/2026
754/1000
Fair
Baa
ManageEngine IAM Global Score (TPRM)
xxxx
ManageEngine IAMSoftware Development
Score locked

ManageEngine IAMFair
Current Score
754Baa (FAIR)
01000
1 incidents
-2 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
756
Vulnerability
03 Jun 2026 • ManageEngine IAM
ADAudit Plus, ADSelfService Plus, ManageEngine and M365 Manager Plus: ManageEngine AD360 Integrated Products Hit by Account Takeover Vulnerability
ManageEngine Patches Critical Account Takeover Flaw in AD360 Suite (CVE-2026-11374)
754
CRITICAL-2
MANMAN1782397883
ManageEngine Patches Critical Account Takeover Flaw in AD360 Suite (CVE-2026-11374)
ManageEngine has disclosed a critical vulnerability, CVE-2026-11374, enabling unauthenticated account takeovers in its AD360 identity and access management suite. The flaw affects multiple integrated products ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus when used with AD360 via single sign-on (SSO).
The vulnerability stems from predictable SSO ticket generation, allowing attackers to craft or guess valid authentication tokens without credentials. Successful exploitation grants access to a user’s identity and role, potentially leading to full account compromise, privilege escalation, or lateral movement within enterprise networks.
Affected versions include:
- ADSelfService Plus (builds ≤6528, patched in 6529 on June 3, 2026)
- RecoveryManager Plus (builds ≤6320, patched in 6321 on June 5, 2026)
- M365 Manager Plus (builds ≤4816, patched in 4817 on June 10, 2026)
- ADAudit Plus (builds ≤8702, patched in 8703 on June 12, 2026)
ManageEngine addressed the issue by strengthening SSO ticket generation to prevent predictability. The vulnerability was responsibly disclosed by security researcher 0xmanhnv via the Zoho BugBounty program.
Given AD360’s role in managing Active Directory, password self-service, auditing, and Microsoft 365 administration, the flaw poses a high-risk threat to enterprises relying on these tools. Organizations are urged to apply patches immediately due to the vulnerability’s pre-authentication nature.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
MAY 2026
756
APRIL 2026
756
MARCH 2026
756
FEBRUARY 2026
756
JANUARY 2026
756
DECEMBER 2025
756
NOVEMBER 2025
756
OCTOBER 2025
756
SEPTEMBER 2025
756
AUGUST 2025
756
JULY 2025
756
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for ManageEngine IAM ??
What was ManageEngine IAM's A.I Rankiteo Cyber Score in May 2026 ??
What was ManageEngine IAM's A.I Rankiteo Cyber Score in April 2026 ??
What was ManageEngine IAM's A.I Rankiteo Cyber Score in March 2026 ??
What was ManageEngine IAM's A.I Rankiteo Cyber Score in February 2026 ??
What was ManageEngine IAM's A.I Rankiteo Cyber Score in January 2026 ??
What was ManageEngine IAM's A.I Rankiteo Cyber Score in December 2025 ??
What was ManageEngine IAM's A.I Rankiteo Cyber Score in November 2025 ??
What was ManageEngine IAM's A.I Rankiteo Cyber Score in October 2025 ??
What was ManageEngine IAM's A.I Rankiteo Cyber Score in September 2025 ??
What was ManageEngine IAM's A.I Rankiteo Cyber Score in August 2025 ??
What was ManageEngine IAM's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on ManageEngine IAM's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with ManageEngine IAM ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view ManageEngine IAM's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?