oM noM Security Feeds cve
vulnerability context

CVE-2026-11374

CVSS 9.0 CRITICALEPSS 65%CWE-287OTX 4 pulses

In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by an unauthenticated user, leading to account takeover.

Published 2026-06-23 · last modified 2026-06-24

details

CISA KEV status
Not in catalog
CVSS v3
9.0 / CRITICAL
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS
65% percentile (score 0.0124)
CWE
CWE-287
OTX pulses
4 total, 0 recent

source mentions 2

source consensus

  • Bluesky
Want the 3-bullet summary of CVE-2026-11374, plus webhook alerts when KEV is updated? Pro is $10/mo.