← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 23, 2026 · 10:21via CyberPress

ManageEngine ADSelfService Plus Flaw Lets Unauthenticated Attackers Execute Code as SYSTEM

Brief

ManageEngine has fixed a high-severity remote code execution vulnerability in ADSelfService Plus that could allow an unauthenticated attacker with physical access to a Windows logon screen to execute arbitrary code as NT AUTHORITY\SYSTEM.

Tracked as CVE-2026-74849, the flaw affects the product’s GINA client component, which integrates ADSelfService Plus password reset and account-unlock functions into the Windows logon experience.

The issue affects ADSelfService Plus builds 7000 and earlier and was fixed in build 7001, released on August 24, 2026.

ManageEngine ADSelfService Plus Flaw

The vulnerable GINA client presents the ADSelfService Plus self-service password reset and account unlock portal directly on the Windows sign-in screen. It uses an embedded kiosk browser to enable users to access those recovery capabilities before authenticating to Windows.

Read more on CyberPress