CISA announced that a security flaw found in Zoho Manage Engine is now classified as an exploited vulnerability based on recent evidence of its active exploitation.
An unspecified vulnerability in Zoho ManageEngine PAM360, Password Manager Pro, and Access Manager Plus could allow for remote code execution, according to a notice from the agency.
“Zoho ManageEngine PAM360, Password Manager Pro, and Access Manager Plus contain an unspecified vulnerability which allows for remote code execution,”
The most severe vulnerability, tracked as CVE-2022-35405, has a CVSS score of 9.8 out of 10 and was fixed by Zoho via updates released on June 24, 2022.
Although the nature of the vulnerability is unknown, the India-based business solutions firm said it fixed it by eliminating any vulnerable components that might allow for remote code execution.
Zoho has also warned the public about the availability of a proof-of-concept (PoC) exploit for the vulnerability. This means that customers must upgrade their instances of Password Manager Pro, PAM360, and Access Manager Plus as soon as possible.
The vulnerability was discovered after a cybersecurity firm and the FBI collaborated on investigating the virus’s source. The agency did not provide further details on how the flaw is being used as a weapon or how widespread the exploit attempts are, but data from GreyNoise revealed that in-the-wild assaults were detected on September 7, 2022.
In light of the active exploitation of the vulnerability, Federal Civilian Executive Branch (FCEB) agencies are required to apply the vendor-provided patches by October 13, 2022. As anyone who has ever tried to patch a hole knows, it’s not always an easy task. In this case, the FCEB has its work cut out for it. The good news is that there are different ways to make patching easier.
More Stories
Killnet and AnonymousSudan Collaborate to Launch Cyber Attacks on Western Organisations
In recent news, it has been reported that two Russia-sympathetic hacktivist groups, Killnet and AnonymousSudan, have allegedly launched a series...
$4000 Gone In An Instant: Mother Defrauded in Facebook Marketplace Car Deal
A mother of four is warning others to be cautious after believing she had purchased a safe and dependable car...
Shocking Scam: Sydney Family Loses $200K Life-Savings in Suncorp Spoofing Fraud
A family from Sydney has lost their life savings worth $200,000 due to a fraudulent scam. Peter and Madison, who...
Mysterious Money Transfer Leaves Couple Speechless: How They Got an Unsolicited $4000
A young couple in Melbourne claims their bank is making up a personal loan they do not understand. Ashley and...
Phishing + AI + Voice Cloning= Big Trouble: The New Way Criminals are Stealing Your Money
New Alert: Criminals use AI and voice cloning to trick you out of your money. Earlier this year, Microsoft unveiled...
‘Impossible to Spot’ Delivery Scam Email Targets Australia Post Customers – Don’t Fall Victim!
Unsuspecting shoppers should be cautious as a parcel delivery scam that is hard to distinguish targets Australia Post customers. Email...