Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
ManageEngine

ManageEngine Vendor Cyber Rating & Cyber Score

manageengine.com

ManageEngine crafts the industry's broadest suite of IT management software. We have everything you need—more than 60+ enterprise products and 60+ free tools—to manage all of your IT operations, from networks and servers to applications, service desk, Active Directory, security, desktops, and mobile devices. Since 2002, IT teams like yours have turned to us for affordable, feature-rich software that's easy to use. You can find our on-premises and cloud solutions powering the IT of over 280,000 companies around the world, including nine of every ten Fortune 100 companies. As you prepare for the IT management challenges ahead, we'll lead the way with new solutions, contextual integrations, and other advances that can only come from a


ManageEngine A.I CyberSecurity Scoring

ManageEngine
Company Information
Website:https://www.manageengine.com
Employees number:587
Number of followers:55,556
NAICS:5112
Industry Type:Software Development
Homepage:manageengine.com
ManageEngine Risk Score (AI oriented)
Between 600 and 649
logo
ManageEngineSoftware Development
Updated:
23/06/2026
641/1000
Poor
Caa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
ManageEngine Global Score (TPRM)
xxxx
logo
ManageEngineSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

ManageEngine
ManageEnginePoor
Current Score
641Caa (POOR)
01000
4 incidents
-67 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
662Before Incident
Cyber Attack
22 Jun 2026ManageEngine
ManageEngine and WhatsApp: WhatsApp phishing attack uses fake business docs to hack PCs

Global WhatsApp Malware Campaign Exploits Compromised Accounts to Spread Remote Access Tools

641After Incident
CRITICAL-21
MANWHA1782174233
Global WhatsApp Malware Campaign Exploits Compromised Accounts to Spread Remote Access Tools An active malware campaign is targeting WhatsApp users across at least 11 countries, including Brazil, India, Mexico, Singapore, the UK, Spain, Taiwan, Australia, Russia, Vietnam, and Malaysia. The attack leverages hijacked WhatsApp accounts to distribute malicious VBScript files disguised as business or financial documents such as billing statements or account notices sent by trusted contacts. Once executed, the VBScript initiates a multi-stage infection chain. It disables User Account Control (UAC) protections via Registry modifications and downloads a ZIP archive containing ManageEngine Endpoint Central, a legitimate IT management tool. The software is silently installed and configured to connect to attacker-controlled servers, granting threat actors remote administrative access to the victim’s system. Kaspersky’s telemetry reveals that the campaign’s infrastructure overlaps with IPs previously linked to ValleyRAT and Gh0st RAT activity, with traces of Chinese language use. However, attribution remains inconclusive. The method used to compromise the initial WhatsApp accounts also remains unclear. The attack exploits both WhatsApp Web (requiring manual file downloads) and the WhatsApp Desktop client (where files can execute automatically via Windows Script Host). While the campaign’s scope is global, its reliance on social engineering particularly through localized filenames highlights its adaptability to regional targets.
INCIDENT DETAILS -
TYPE
Malware Campaign
IMPACT
Systems Affected: Victim systems with remote administrative access granted to attackers
DATA BREACH
VBScriptZIP
MAY 2026
659Before Incident
APRIL 2026
658Before Incident
MARCH 2026
656Before Incident
FEBRUARY 2026
654Before Incident
JANUARY 2026
651Before Incident
DECEMBER 2025
648Before Incident
NOVEMBER 2025
647Before Incident
OCTOBER 2025
644Before Incident
SEPTEMBER 2025
642Before Incident
AUGUST 2025
750Before Incident
Ransomware
06 Aug 2025ManageEngine
ManageEngine

SEO Poisoning Campaign Distributing Bumblebee Malware Leading to Akira Ransomware Attacks

637After Incident
CRITICAL-113
MAN305080925
A sophisticated SEO poisoning campaign exploited Bing search results to distribute Bumblebee malware, leading to Akira ransomware attacks. Users searching for ManageEngine OpManager were redirected to a malicious site hosting a trojanized installer. The malware established command and control communications, escalated privileges, and exfiltrated domain account hashes. The attack culminated in ransomware deployment, encrypting systems within 44 hours and compromising child domains, causing significant operational disruption and data loss.
INCIDENT DETAILS -
TYPE
Malware, Ransomware
MOTIVATION
Financial gain, Data exfiltration
IMPACT
Data Compromised: Password hashes, Domain account informationSystems Affected: Enterprise networks, Domain controllersOperational Impact: Domain-wide administrative privileges obtained, Ransomware encryptionIdentity Theft Risk: High
DATA BREACH
Type Of Data Compromised: Password hashes, Domain account informationSensitivity Of Data: HighData Exfiltration: YesData Encryption: YesFile Types Exposed: NTDS.dit, SYSTEM, SECURITY
JULY 2025
751Before Incident
JUNE 2025
754Before Incident
Vulnerability
10 Jun 2025ManageEngine
ManageEngine

ManageEngine Exchange Reporter Plus RCE Flaw

750After Incident
CRITICAL-4
MAN144061025
A severe security vulnerability identified as CVE-2025-3835 has been found in ManageEngine Exchange Reporter Plus. This vulnerability allows attackers to execute arbitrary commands on target servers through a flaw in the Content Search module. The vulnerability affects all installations with build 5721 and below. Security experts advise immediate updates to prevent complete system compromise, potential data breaches, and further malicious activities such as ransomware deployment.
INCIDENT DETAILS -
TYPE
Remote Code Execution (RCE)
MOTIVATION
Complete system compromisePotential data breachesEstablish persistent accessMove laterally within networksExfiltrate sensitive dataDeploy additional malicious payloads such as ransomware
IMPACT
Systems Affected: All Exchange Reporter Plus installations with build 5721 and below
MARCH 2025
756Before Incident
Vulnerability
11 Mar 2025ManageEngine
ManageEngine

Authentication Vulnerability in ManageEngine Analytics Plus

754After Incident
CRITICAL-2
MAN710031725
A high-severity authentication vulnerability, identified as CVE-2025-1724, affected ManageEngine Analytics Plus on-premise versions before the 6130 build. Malicious actors could exploit the flaw to bypass AD authentication, gaining unauthorized access to user accounts and sensitive data. The issue was patched on March 11, 2025. Key management and encryption weaknesses allowed token capture and replay, leading to potential account takeovers and exposing organizations to data exfiltration, regulatory non-compliance, and escalation of privileges.
INCIDENT DETAILS -
TYPE
Authentication Vulnerability
MOTIVATION
Unauthorized access to user accounts and sensitive data
IMPACT
user accountssensitive data
DATA BREACH
user accountssensitive dataData Exfiltration: Potential data exfiltrationData Encryption: Key management and encryption weaknesses

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for ManageEngine ?
?
What was ManageEngine's A.I Rankiteo Cyber Score in May 2026 ?
?
What was ManageEngine's A.I Rankiteo Cyber Score in April 2026 ?
?
What was ManageEngine's A.I Rankiteo Cyber Score in March 2026 ?
?
What was ManageEngine's A.I Rankiteo Cyber Score in February 2026 ?
?
What was ManageEngine's A.I Rankiteo Cyber Score in January 2026 ?
?
What was ManageEngine's A.I Rankiteo Cyber Score in December 2025 ?
?
What was ManageEngine's A.I Rankiteo Cyber Score in November 2025 ?
?
What was ManageEngine's A.I Rankiteo Cyber Score in October 2025 ?
?
What was ManageEngine's A.I Rankiteo Cyber Score in September 2025 ?
?
What was ManageEngine's A.I Rankiteo Cyber Score in August 2025 ?
?
What was ManageEngine's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on ManageEngine's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with ManageEngine ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view ManageEngine's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?