Synced 17 Jun 2026 22:27 UTC Account
← ManageEngine

ManageEngine vulnerabilities: known CVEs & security history

Zoho · Actively exploited · 26 tracked CVEs · 1 actively exploited · updated June 2026 · what is a CVE? →

This is the full list of known vulnerabilities (CVEs) across all ManageEngine release lines — 26 in total, with 1 actively exploited in the wild. A CVE here doesn't mean your version is affected — check ManageEngine's current status and the safe version to run.

26
known CVEs
1
actively exploited (KEV)
3
critical severity
1
ransomware-linked

Known ManageEngine CVEs

Actively-exploited and most-severe first. Open any CVE for full details.

CVESeverityCVSSEPSSYear
CVE-2022-47966⚡ exploited critical 9.8 100% 2023
CVE-2021-20110 critical 9.8 7% 2021
CVE-2019-12994 critical 9.1 4% 2019
CVE-2019-12959 high 8.8 3% 2019
CVE-2019-14693 high 8.5 4% 2019
CVE-2023-35785 high 8.1 2% 2023
CVE-2023-26601 high 7.5 34% 2023
CVE-2022-35403 high 7.5 7% 2022
CVE-2021-20109 high 7.5 1% 2021
CVE-2021-20108 high 7.5 3% 2021
CVE-2019-19034 high 7.2 6% 2020
CVE-2023-26600 medium 6.5 6% 2023
CVE-2022-40772 medium 6.5 3% 2022
CVE-2020-8838 medium 6.4 2% 2020
CVE-2023-23075 medium 6.1 3% 2023
CVE-2019-12597 medium 6.1 2% 2019
CVE-2019-12596 medium 6.1 2% 2019
CVE-2019-12595 medium 6.1 2% 2019
CVE-2019-12537 medium 6.1 2% 2019
CVE-2018-17596 medium 6.1 2% 2018
CVE-2023-6105 medium 5.5 1% 2023
CVE-2023-29443 medium 4.9 3% 2023
CVE-2022-40771 medium 4.9 3% 2022
CVE-2015-2169 medium 4.3 8% 2015
CVE-2012-5956 medium 4.3 4% 2012
CVE-2015-5061 low 3.5 2% 2015

Is my ManageEngine version affected?

The list above spans every release. To know whether your version is affected — and the minimum safe version to upgrade to — check it directly.

Check your ManageEngine version → · Monitor ManageEngine for new CVEs →

ManageEngine vulnerabilities — frequently asked

How many known vulnerabilities does ManageEngine have?

IsItPatched tracks 26 CVEs for ManageEngine, 1 of which is actively exploited (CISA KEV). 3 are critical-severity and 8 high-severity. These span every release line — what matters is whether the version you run is affected.

Does ManageEngine have any actively-exploited vulnerabilities?

Yes — 1 ManageEngine CVE is in CISA's Known Exploited Vulnerabilities catalog, meaning it is confirmed exploited in the wild (1 linked to ransomware). Patch it as a priority.

What is the most severe ManageEngine vulnerability?

Among tracked issues, CVE-2022-47966 (CRITICAL, CVSS 9.8), which is actively exploited, ranks highest — a Improper input validation weakness.

Is ManageEngine safe to use?

It depends on the version. The latest supported ManageEngine release clears the known issues; older versions may still be affected. Check the exact version you run for a verdict.

CVE data aggregated from NVD, CISA KEV and EPSS (FIRST.org). Related: ManageEngine security status · ManageEngine end-of-life · actively-exploited CVEs. Always verify against Zoho's advisories — see our disclaimer.