<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>0dayNews — Zoho</title><description>Vulnerabilities in Zoho&apos;s ManageEngine suite — ADSelfService Plus, ADAudit Plus, ServiceDesk Plus, and adjacent identity and IT-management tools — where authentication bypasses and unauthenticated RCEs draw APT groups and ransomware operators as quickly as CVEs are published. Combined article + CVE feed for the Zoho beat.</description><link>https://0daynews.com/</link><language>en-us</language><item><title>CVE-2019-8394 — Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability</title><link>https://0daynews.com/cve/cve-2019-8394/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-8394/</guid><description>Zoho ManageEngine ServiceDesk Plus (SDP) contains an unspecified vulnerability that allows remote users to upload files via login page customization.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Zoho</category><category>medium</category><category>cve</category></item><item><title>CVE-2020-10189 — Zoho ManageEngine Desktop Central File Upload Vulnerability</title><link>https://0daynews.com/cve/cve-2020-10189/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-10189/</guid><description>Zoho ManageEngine Desktop Central contains a file upload vulnerability that allows for unauthenticated remote code execution.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Zoho</category><category>critical</category><category>cve</category></item><item><title>CVE-2021-37415 — Zoho ManageEngine ServiceDesk Authentication Bypass Vulnerability</title><link>https://0daynews.com/cve/cve-2021-37415/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-37415/</guid><description>Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Zoho</category><category>critical</category><category>cve</category></item><item><title>CVE-2021-40539 — Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability</title><link>https://0daynews.com/cve/cve-2021-40539/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-40539/</guid><description>Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Zoho</category><category>critical</category><category>cve</category></item><item><title>CVE-2021-44077 — Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2021-44077/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-44077/</guid><description>Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Zoho</category><category>critical</category><category>cve</category></item><item><title>CVE-2021-44515 — Zoho Desktop Central Authentication Bypass Vulnerability</title><link>https://0daynews.com/cve/cve-2021-44515/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-44515/</guid><description>Zoho Desktop Central contains an authentication bypass vulnerability that could allow an attacker to execute arbitrary code in the Desktop Central MSP server.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Zoho</category><category>critical</category><category>cve</category></item><item><title>CVE-2022-28810 — Zoho ManageEngine ADSelfService Plus Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2022-28810/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-28810/</guid><description>Zoho ManageEngine ADSelfService Plus contains an unspecified vulnerability allowing for remote code execution when performing a password change or reset.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Zoho</category><category>medium</category><category>cve</category></item><item><title>CVE-2022-35405 — Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2022-35405/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-35405/</guid><description>Zoho ManageEngine PAM360, Password Manager Pro, and Access Manager Plus contain an unspecified vulnerability that allows for remote code execution.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Zoho</category><category>critical</category><category>cve</category></item><item><title>CVE-2022-47966 — Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2022-47966/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-47966/</guid><description>Multiple Zoho ManageEngine products contain an unauthenticated remote code execution vulnerability due to the usage of an outdated third-party dependency, Apache Santuario.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Zoho</category><category>critical</category><category>cve</category></item></channel></rss>