ManageEngine ADSelfService Plus CVE-2026-74849 (High / WASOC CVSS 9.8): GINA logon-screen embedded browser → SYSTEM RCE (fix 7001); WASOC 20260924001
Zoho ManageEngine security advisory for CVE-2026-74849 documents remote code execution in the ADSelfService Plus GINA client — the self-service password-reset / account-unlock portal shown on the Windows logon screen via an embedded (kiosk) browser. An unauthenticated attacker with access to the Windows logon screen may leverage the embedded browser to execute code as NT AUTHORITY\SYSTEM and fully compromise the host. Vendor severity High. Affected: builds 7000 and below. Fixed: build 7001 (fixed on 24 August 2026) by correcting error handling and hardening the embedded logon-screen browser; update via the service pack. Reported by Marouane Belabbassi and Amjad E Alhejaili via Zoho BugBounty. Industry wires (Cyber Security News 23 Sep 2026) amplified the advisory and cited a CVSS 9.8 figure not printed on the vendor advisory page — desk records vendor High only. No in-the-wild exploitation claimed in the vendor advisory. WASOC advisory 20260924001 (24 Sep 2026) lists CVE-2026-74849 as Critical CVSS 9.8 (versions 7000 and below) alongside Applications Manager CVE-2026-86708 and OpManager MSP CVE-2026-19599, and states no exploitation observed on WA Government networks at time of writing — desk keeps vendor High as the primary severity label and records WASOC’s 9.8 as the AU SOC figure. Primary: ManageEngine CVE-2026-74849 advisory; AU: WASOC 20260924001.
- Product
- Zoho ManageEngine ADSelfService Plus GINA client (Windows logon embedded browser)
- Versions
- Affected: ADSelfService Plus builds 7000 and below. Fixed: build 7001 (24 Aug 2026) and later via service pack.
- CVSS
- High (ManageEngine advisory; no CVSS vector published on vendor page)
- Exploited in Australia?
- unknown
- Patch to
- Upgrade ADSelfService Plus to build 7001 or later using the vendor service pack; inventory Windows endpoints with the GINA/logon-screen self-service client; restrict physical/console access to untrusted logon screens where possible until patched
Primary: ManageEngine — CVE-2026-74849 ADSelfService Plus GINA client RCE · Vendor: ManageEngine Self-Service Password — security advisory CVE-2026-74849 · CVE: CVE-2026-74849, CVE-2026-86708, CVE-2026-19599 · WASOC 20260924001 — ManageEngine Critical Vulnerabilities (24 Sep 2026)
