CVE / RCE
CVE-2025-9223: Command Execution Bypass in ManageEngine Applications Manager
How a poorly implemented command blacklist in the "Execute Program Action" function allows authenticated remote code execution, completely bypassing the security restrictions.
Read full case study