Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

CVE-2026-11374 -- CVSS 9.0 Vulnerability Briefing

CVE-2026-11374 | CVSS 9.0 (Critical) | Exploit: No known exploit

What Is It

CVE-2026-11374 is a predictable session token vulnerability affecting the Single Sign-On (SSO) authentication mechanism in Zoho ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, allowing unauthenticated attackers to forge valid session tickets.

Technical Detail

The flaw resides in the SSO ticket generation logic used to authenticate user sessions across the affected ManageEngine products. An unauthenticated attacker who can observe or interact with the authentication flow may predict valid SSO ticket values due to insufficient randomness or a flawed token construction algorithm, enabling session hijacking without supplying valid credentials. Successful exploitation results in authentication bypass, granting the attacker access to the application at the privilege level of the targeted session, which in identity and directory management tools of this class could include administrative access to Active Directory, Microsoft 365 environments, or audit log data.

Exploitation Status

No known exploit code has been publicly identified at this time, and this CVE is not currently listed in the CISA Known Exploited Vulnerabilities catalog. The exploit maturity is assessed as no known exploit, meaning no public proof-of-concept or operational tooling has been confirmed as of June 30, 2026. However, the high CVSS score of 9.0 and the nature of the flaw make it a credible target for development of working exploits.

Who Is Targeting This

No confirmed, ATTAX-verified threat actor attribution exists for this CVE at this time. Reported (research-inferred) associations at medium confidence include DEEPPANDA, VOLATILECEDAR, LOTUSBLOSSOM, SEATURTLE, and AGRIUS. These associations are research-inferred and have not been independently confirmed through observed exploitation of this specific vulnerability. Motivations and origins for these actors are not specified in available reporting. The presence of actors historically associated with espionage and destructive operations in this list warrants monitoring, but attribution should not be treated as confirmed.

What To Do

Organizations running ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, or ADAudit Plus should apply vendor-supplied patches as soon as they become available, treating this as a high-priority remediation given the authentication bypass impact and the critical CVSS rating. Until patching is complete, restrict network access to the affected management interfaces to trusted IP ranges and enforce additional authentication controls at the network perimeter where possible. Monitor authentication logs for anomalous SSO ticket usage, including successful logins from unexpected source addresses or at unusual times. Review administrative session activity across connected Active Directory and Microsoft 365 environments for signs of unauthorized access. Check Zoho ManageEngine's security advisory pages directly for patch availability and version-specific guidance, as affected version ranges have not been fully enumerated in current public data.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →