CVE-2022-47966CISA KEVEPSS p100.0%

CVE-2022-47966Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability

Zoho / ManageEngine

Description

Multiple Zoho ManageEngine products contain an unauthenticated remote code execution vulnerability due to the usage of an outdated third-party dependency, Apache Santuario.

Scoring

CVSS 9.8 ()
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS99.75% probability of exploitation · percentile 100.0% · 2026-07-28T12:00:27Z
Last modified2026-07-31

CISA KEV entry

Added to KEV: 2023-01-23

(incoming)1

TypeTargetConfidenceTier
KEVEntryZoho ManageEngine Multiple Products Remote Code Execution Vulnerabilitykev-cve-2022-479660%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability
CVE
Zoho ManageEngine ADSelfService Plus Remote Code Execution Vulnerability
CVE
Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability
CVE
Zoho ManageEngine ServiceDesk Authentication Bypass Vulnerability
CVE
CVE-2025-9223
CVE
Zoho ManageEngine Desktop Central File Upload Vulnerability
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.