ManageEngine ADAudit Plus 8703
ManageEngine ADAudit Plus Build 8703 is a security-focused maintenance release that addresses multiple vulnerabilities, including a high-severity SQL injection flaw (CVE-2026-12062) and an account takeover vulnerability affecting AD360 SSO integration (CVE-2026-11374). The release also enhances secure agent communication and resolves several authorization-related issues.
- Fixed a high-severity SQL injection vulnerability (CVE-2026-12062) in the Reports API.
- Resolved an account takeover vulnerability (CVE-2026-11374) affecting AD360 single sign-on integration.
- Added SSL certificate validation for agent-to-server HTTPS communication.
- Extended secure communication settings (TLS, ciphers, certificates, and keystore configuration) to agent-server communication.
What's new
ManageEngine has released ADAudit Plus Build 8703, a maintenance update focused on security, secure communications, and platform reliability.
This release resolves multiple security vulnerabilities while improving authorization controls and strengthening encrypted communication between agents and the ADAudit Plus server.
- Fixed the high-severity SQL injection vulnerability CVE-2026-12062.
- Resolved the account takeover vulnerability CVE-2026-11374 affecting AD360 SSO integration.
- Added SSL certificate validation for agent-to-server HTTPS communication.
- Applied secure communication settings (TLS, SSL certificates, cipher suites, and keystore configuration) to agent-server communication.
- Fixed authorization issues that allowed unauthorized access to Mail Server configuration settings.
- Resolved an issue allowing technicians to delete favorite reports created by other technicians.
- Updated the ADAudit Plus data collection agent.
- Included additional reliability and maintenance improvements.
ManageEngine strongly recommends upgrading to Build 8703 to address the latest security vulnerabilities and improve the overall security posture of ADAudit Plus deployments.
๐ฌ Comments (0)
No comments yet.