References https://www.manageengine.com/products/desktop-central/remote-code-execution-vulnerability.html https://www.sentinelone.com/vulnerability-database/cve-2020-10189/ https://threatprotect.qualys.com/2020/03/11/manageengine-desktop-central-unauthenticated-remote-code-execution-vulnerability-cve-2020-10189/ https://nvd.nist.gov/vuln/detail/cve-2020-10189 https://www.rapid7.com/db/vulnerabilities/http-manageengine-dc-cve-2020-10189/ https://www.broadcom.com/support/security-center/attacksignatures/detail?asid=32109 https://www.manageengine.com/products/desktop-central/cve-2021-44757.html https://www.cisa.gov/news-events/alerts/2022/01/19/zoho-releases-security-advisory-manageengine-desktop-central-and-desktop-central-msp https://it.ucsf.edu/actively-exploited-critical-vulnerability-zoho-manageengine-desktop-and-desktop-central https://www.manageengine.com/products/desktop-central/privilege-escalation-endpointcentral-agent.html https://nvd.nist.gov/vuln/detail/CVE-2024-10203 https://www.manageengine.com/products/desktop-central/cve-2021-46165.html https://labs.jumpsec.com/zoho-manageengine-desktop-central-path-traversal-arbitrary-file-write/ https://www.manageengine.com/desktop-management-msp/cve-2021-44515-security-advisory.html https://www.secpod.com/blog/zoho-patches-a-critical-vulnerability-in-its-manageengine-desktop-central-solutions https://nvd.nist.gov/vuln/detail/cve-2022-47966
Related VulnerabilitiesPoCCVE-2026-86206: N-able N-central - Access Control Bypass via Path Confusion and Forwarded Header SpoofingPoCCVE-2026-86207: N-able N-central - Authentication Bypass旭辰資訊|SmartIT Desktop Manager - 存在4個漏洞PoCCVE-2026-18577: N-able N-central < 2026.3.1.10 - Authentication BypassPoCCVE-2019-1003030: Jenkins Pipeline Groovy Plugin <=2.63 - Insecure DeserializationPoCCVE-2026-3001: Gutenverse Plugin <= 3.4.6 - Cross-Site ScriptingPoCCVE-2025-6389: Sneeit WP Social WordPress Plugin - Unauthenticated RCE via call_user_funcPoCCVE-2026-3296: Everest Forms WordPress Plugin <= 3.4.3 - PHP Object InjectionPoCNginxWebUI /adminPage/login/getAuth 命令执行漏洞PoCNginxWebUI /Adminpage/Conf/loadOrg 文件读取漏洞NginxWebUI /Api/Nginx/runNginxCmd 命令执行漏洞NginxWebUI /Adminpage/Remote/cmdOver 命令执行漏洞Stripe Payment Plugin for WooCommerce /wc-api/WT_Stripe/ SQL 注入漏洞(CVE-2024-0705)