ManageEngine A.I CyberSecurity Scoring
ManageEngine
Company Information
Website:https://www.manageengine.com
Employees number:587
Number of followers:55,556
NAICS:5112
Industry Type:Software Development
Homepage:manageengine.com
ManageEngine Risk Score (AI oriented)
Between 600 and 649
ManageEngineSoftware Development
Updated:
23/06/2026
23/06/2026
641/1000
Poor
Caa
ManageEngine Global Score (TPRM)
xxxx
ManageEngineSoftware Development
Score locked

ManageEnginePoor
Current Score
641Caa (POOR)
01000
4 incidents
-67 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
662
Cyber Attack
22 Jun 2026 • ManageEngine
ManageEngine and WhatsApp: WhatsApp phishing attack uses fake business docs to hack PCs
Global WhatsApp Malware Campaign Exploits Compromised Accounts to Spread Remote Access Tools
641
CRITICAL-21
MANWHA1782174233
Global WhatsApp Malware Campaign Exploits Compromised Accounts to Spread Remote Access Tools
An active malware campaign is targeting WhatsApp users across at least 11 countries, including Brazil, India, Mexico, Singapore, the UK, Spain, Taiwan, Australia, Russia, Vietnam, and Malaysia. The attack leverages hijacked WhatsApp accounts to distribute malicious VBScript files disguised as business or financial documents such as billing statements or account notices sent by trusted contacts.
Once executed, the VBScript initiates a multi-stage infection chain. It disables User Account Control (UAC) protections via Registry modifications and downloads a ZIP archive containing ManageEngine Endpoint Central, a legitimate IT management tool. The software is silently installed and configured to connect to attacker-controlled servers, granting threat actors remote administrative access to the victim’s system.
Kaspersky’s telemetry reveals that the campaign’s infrastructure overlaps with IPs previously linked to ValleyRAT and Gh0st RAT activity, with traces of Chinese language use. However, attribution remains inconclusive. The method used to compromise the initial WhatsApp accounts also remains unclear.
The attack exploits both WhatsApp Web (requiring manual file downloads) and the WhatsApp Desktop client (where files can execute automatically via Windows Script Host). While the campaign’s scope is global, its reliance on social engineering particularly through localized filenames highlights its adaptability to regional targets.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
MAY 2026
659
APRIL 2026
658
MARCH 2026
656
FEBRUARY 2026
654
JANUARY 2026
651
DECEMBER 2025
648
NOVEMBER 2025
647
OCTOBER 2025
644
SEPTEMBER 2025
642
AUGUST 2025
750
Ransomware
06 Aug 2025 • ManageEngine
ManageEngine
SEO Poisoning Campaign Distributing Bumblebee Malware Leading to Akira Ransomware Attacks
637
CRITICAL-113
MAN305080925
A sophisticated SEO poisoning campaign exploited Bing search results to distribute Bumblebee malware, leading to Akira ransomware attacks. Users searching for ManageEngine OpManager were redirected to a malicious site hosting a trojanized installer. The malware established command and control communications, escalated privileges, and exfiltrated domain account hashes. The attack culminated in ransomware deployment, encrypting systems within 44 hours and compromising child domains, causing significant operational disruption and data loss.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JULY 2025
751
JUNE 2025
754
Vulnerability
10 Jun 2025 • ManageEngine
ManageEngine
ManageEngine Exchange Reporter Plus RCE Flaw
750
CRITICAL-4
MAN144061025
A severe security vulnerability identified as CVE-2025-3835 has been found in ManageEngine Exchange Reporter Plus. This vulnerability allows attackers to execute arbitrary commands on target servers through a flaw in the Content Search module. The vulnerability affects all installations with build 5721 and below. Security experts advise immediate updates to prevent complete system compromise, potential data breaches, and further malicious activities such as ransomware deployment.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
MARCH 2025
756
Vulnerability
11 Mar 2025 • ManageEngine
ManageEngine
Authentication Vulnerability in ManageEngine Analytics Plus
754
CRITICAL-2
MAN710031725
A high-severity authentication vulnerability, identified as CVE-2025-1724, affected ManageEngine Analytics Plus on-premise versions before the 6130 build. Malicious actors could exploit the flaw to bypass AD authentication, gaining unauthorized access to user accounts and sensitive data. The issue was patched on March 11, 2025. Key management and encryption weaknesses allowed token capture and replay, leading to potential account takeovers and exposing organizations to data exfiltration, regulatory non-compliance, and escalation of privileges.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for ManageEngine ??
What was ManageEngine's A.I Rankiteo Cyber Score in May 2026 ??
What was ManageEngine's A.I Rankiteo Cyber Score in April 2026 ??
What was ManageEngine's A.I Rankiteo Cyber Score in March 2026 ??
What was ManageEngine's A.I Rankiteo Cyber Score in February 2026 ??
What was ManageEngine's A.I Rankiteo Cyber Score in January 2026 ??
What was ManageEngine's A.I Rankiteo Cyber Score in December 2025 ??
What was ManageEngine's A.I Rankiteo Cyber Score in November 2025 ??
What was ManageEngine's A.I Rankiteo Cyber Score in October 2025 ??
What was ManageEngine's A.I Rankiteo Cyber Score in September 2025 ??
What was ManageEngine's A.I Rankiteo Cyber Score in August 2025 ??
What was ManageEngine's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on ManageEngine's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with ManageEngine ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view ManageEngine's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?