Critical Unauthenticated RCE in ManageEngine ADAudit Plus: Immediate Patch Required (CVE-2026-6516)
Overview
CVE-2026-6516 is a CVSS-10.0 unauthenticated remote code execution (RCE) flaw in ManageEngine ADAudit Plus versions before 8606. Exploitation allows attackers to execute arbitrary commands on enterprise servers with elevated privileges, risking total domain compromise.
Technical Analysis
The vulnerability resides in the agent API (defaulting to port 8081), which lacks authentication and accepts malicious payloads via crafted HTTP requests. Attackers can trigger system command execution by injecting payloads into API parameters, bypassing all access controls. This requires no user interaction or credentials, enabling direct host exploitation from remote networks.
Enterprise & DIB Impact
For Defense Industrial Base (DIB) and enterprise environments, successful exploitation could lead to full Active Directory access, data exfiltration, lateral movement, and operational disruption. ADAudit Plus deployments are often deeply integrated with critical infrastructure, making this a catastrophic risk if unpatched.
Recommended Actions
- Upgrade ADAudit Plus to version 8606 or later immediately
- restrict network access to the agent API endpoint using firewalls
- deploy logging and IDS rules to monitor port 8081 traffic for anomalies
- disable unused APIs to reduce attack surface
- and conduct internal audits for signs of compromise in affected systems.
Need Help Assessing Your Exposure?
Axiom Cyber Research provides vulnerability assessment, red team operations, and security advisory services to the Defense Industrial Base and regulated sectors.
Schedule a ConsultationFull security advisory on 247alerts.net →