Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections, and the ManageEngine applications did not provide those protections. This affects Access Manager Plus before 4308, Active Directory 360 before 4310, ADAudit Plus before 7081, ADManager Plus before 7162, ADSelfService Plus before 6211, Analytics Plus before 5150, Application Control Plus before 10.1.2220.18, Asset Explorer before 6983, Browser Security Plus before 11.1.2238.6, Device Control Plus before 10.1.2220.18, Endpoint Central before 10.1.2228.11, Endpoint Central MSP before 10.1.2228.11, Endpoint DLP before 10.1.2137.6, Key Manager Plus before 6401, OS Deployer before 1.1.2243.1, PAM 360 before 5713, Password Manager Pro before 12124, Patch Manager Plus before 10.1.2220.18, Remote Access Plus before 10.1.2228.11, Remote Monitoring and Management (RMM) before 10.1.41. ServiceDesk Plus before 14004, ServiceDesk Plus MSP before 13001, SupportCenter Plus before 11026, and Vulnerability Manager Plus before 10.1.2220.18. Exploitation is only possible if SAML SSO has ever been configured for a product (for some products, exploitation requires that SAML SSO is currently active).
CVE-2022-47966
Score elevated to 9.8 because this CVE is listed on the CISA Known Exploited Vulnerabilities catalog (added 2023-01-23), indicating real-world exploitation has been confirmed by US federal agencies. NVD baseline CVSS 9.8 retained for reference. Confidence: HIGH.
- Actively exploited in the wild (CISA-KEV)
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 9.8
- EG Score
- 9.8(high)
- EG Risk
- 99(Act)EG Risk 99/100SSVC: Act
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity98% × 45%Exploitation100% × 40%Automatability100% × 15%Action: Fix now — active exploitation, automatable, high impact. - EPSS PROB
- 100%
- EPSS %ILE
- 100%
- KEV
- ⚠ Exploited
Published
January 18, 2023
Last Modified
July 31, 2026
Advisory Details (10)
Auto-updated Sep 4, 2026ManageEngine Security Advisories
https://www.manageengine.com/security/advisory/CVE/cve-2022-47966.htmlManageEngine CVE-2022-47966 Technical Deep Dive | Horizon3
https://www.horizon3.ai/manageengine-cve-2022-47966-technical-deep-dive/Multiple Nation-State Threat Actors Exploit CVE-2022-47966 and CVE-2022-42475 | CISA
Multiple Nation-State Threat Actors Exploit CVE-2022-47966 and CVE-2022-42475 | CISA. Listed in CISA Known Exploited Vulnerabilities catalog.
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-250aGitHub - horizon3ai/CVE-2022-47966: POC for CVE-2022-47966 affecting multiple ManageEngine products · GitHub
https://github.com/horizon3ai/CVE-2022-47966Tags · apache/santuario-xml-security-java · GitHub
https://github.com/apache/santuario-xml-security-java/tags?after=1.4.6Rapid7 Analysis: CVE-2022-47966
https://attackerkb.com/topics/gvs0Gv8BID/cve-2022-47966/rapid7-analysisLocked Out | Packet Storm
http://packetstormsecurity.com/files/170943/Zoho-ManageEngine-Endpoint-Central-MSP-10.1.2228.10-Remote-Code-Execution.htmlLocked Out | Packet Storm
http://packetstormsecurity.com/files/170925/ManageEngine-ADSelfService-Plus-Unauthenticated-SAML-Remote-Code-Execution.htmlLocked Out | Packet Storm
http://packetstormsecurity.com/files/170882/Zoho-ManageEngine-ServiceDesk-Plus-14003-Remote-Code-Execution.htmlWeakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 49× in last 7d / 218× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
Showing the most recent 100 of 710 total refreshes for this CVE.
- 2026-09-08 20:45 UTCGHSA enrichment
- 2026-09-08 18:54 UTCCISA KEV update
- 2026-09-08 16:59 UTCGHSA enrichment
- 2026-09-08 13:12 UTCGHSA enrichment
- 2026-09-08 09:26 UTCGHSA enrichment
- 2026-09-08 05:38 UTCGHSA enrichment
- 2026-09-08 01:53 UTCGHSA enrichment
- 2026-09-07 22:07 UTCGHSA enrichment
- 2026-09-07 18:21 UTCGHSA enrichment
- 2026-09-07 14:35 UTCGHSA enrichment
- 2026-09-07 10:46 UTCGHSA enrichment
- 2026-09-07 06:57 UTCGHSA enrichment
- 2026-09-07 03:09 UTCGHSA enrichment
- 2026-09-06 23:24 UTCGHSA enrichment
- 2026-09-06 19:38 UTCGHSA enrichment
- 2026-09-06 15:52 UTCGHSA enrichment
- 2026-09-06 12:05 UTCGHSA enrichment
- 2026-09-06 08:17 UTCGHSA enrichment
- 2026-09-06 04:30 UTCGHSA enrichment
- 2026-09-06 00:45 UTCGHSA enrichment
- 2026-09-05 20:59 UTCGHSA enrichment
- 2026-09-05 17:14 UTCEG score recompute
- 2026-09-05 17:14 UTCGHSA enrichment
- 2026-09-05 15:25 UTCEPSS rescore
- 2026-09-05 13:27 UTCGHSA enrichment
Show 75 moreShow fewer
- 2026-09-05 09:40 UTCGHSA enrichment
- 2026-09-05 05:54 UTCGHSA enrichment
- 2026-09-05 02:08 UTCGHSA enrichment
- 2026-09-04 22:22 UTCGHSA enrichment
- 2026-09-04 18:35 UTCGHSA enrichment
- 2026-09-04 17:38 UTCCISA KEV update
- 2026-09-04 14:47 UTCGHSA enrichment
- 2026-09-04 10:58 UTCGHSA enrichment
- 2026-09-04 07:11 UTCGHSA enrichment
- 2026-09-04 03:26 UTCGHSA enrichment
- 2026-09-03 23:39 UTCGHSA enrichment
- 2026-09-03 19:51 UTCGHSA enrichment
- 2026-09-03 16:05 UTCGHSA enrichment
- 2026-09-03 12:19 UTCGHSA enrichment
- 2026-09-03 08:33 UTCGHSA enrichment
- 2026-09-03 04:45 UTCGHSA enrichment
- 2026-09-03 00:59 UTCGHSA enrichment
- 2026-09-02 21:14 UTCGHSA enrichment
- 2026-09-02 17:33 UTCCISA KEV update
- 2026-09-02 17:28 UTCGHSA enrichment
- 2026-09-02 13:39 UTCGHSA enrichment
- 2026-09-02 09:54 UTCGHSA enrichment
- 2026-09-02 06:08 UTCGHSA enrichment
- 2026-09-02 02:20 UTCGHSA enrichment
- 2026-09-01 22:35 UTCGHSA enrichment
- 2026-09-01 18:49 UTCGHSA enrichment
- 2026-09-01 15:03 UTCGHSA enrichment
- 2026-09-01 11:14 UTCGHSA enrichment
- 2026-09-01 07:27 UTCGHSA enrichment
- 2026-09-01 03:41 UTCGHSA enrichment
- 2026-08-31 23:53 UTCGHSA enrichment
- 2026-08-31 20:08 UTCGHSA enrichment
- 2026-08-31 16:20 UTCGHSA enrichment
- 2026-08-31 14:19 UTCCISA KEV update
- 2026-08-31 12:35 UTCGHSA enrichment
- 2026-08-31 08:50 UTCGHSA enrichment
- 2026-08-31 05:01 UTCGHSA enrichment
- 2026-08-31 01:16 UTCGHSA enrichment
- 2026-08-30 21:30 UTCEG score recompute
- 2026-08-30 21:30 UTCGHSA enrichment
- 2026-08-30 19:15 UTCEPSS rescore
- 2026-08-30 17:45 UTCGHSA enrichment
- 2026-08-30 14:00 UTCGHSA enrichment
- 2026-08-30 10:14 UTCGHSA enrichment
- 2026-08-30 06:28 UTCGHSA enrichment
- 2026-08-30 02:43 UTCGHSA enrichment
- 2026-08-29 22:57 UTCGHSA enrichment
- 2026-08-29 19:11 UTCGHSA enrichment
- 2026-08-29 15:25 UTCGHSA enrichment
- 2026-08-29 11:38 UTCGHSA enrichment
- 2026-08-29 07:51 UTCGHSA enrichment
- 2026-08-29 04:03 UTCGHSA enrichment
- 2026-08-29 00:18 UTCEG score recompute
- 2026-08-29 00:17 UTCGHSA enrichment
- 2026-08-28 21:38 UTCEPSS rescore
- 2026-08-28 20:32 UTCGHSA enrichment
- 2026-08-28 16:46 UTCGHSA enrichment
- 2026-08-28 12:57 UTCGHSA enrichment
- 2026-08-28 09:08 UTCGHSA enrichment
- 2026-08-28 05:21 UTCGHSA enrichment
- 2026-08-28 01:34 UTCGHSA enrichment
- 2026-08-27 21:49 UTCGHSA enrichment
- 2026-08-27 18:03 UTCGHSA enrichment
- 2026-08-27 17:22 UTCCISA KEV update
- 2026-08-27 14:17 UTCGHSA enrichment
- 2026-08-27 10:31 UTCGHSA enrichment
- 2026-08-27 06:45 UTCGHSA enrichment
- 2026-08-27 03:00 UTCGHSA enrichment
- 2026-08-26 23:14 UTCGHSA enrichment
- 2026-08-26 19:29 UTCGHSA enrichment
- 2026-08-26 17:41 UTCCISA KEV update
- 2026-08-26 15:44 UTCGHSA enrichment
- 2026-08-26 11:59 UTCGHSA enrichment
- 2026-08-26 08:14 UTCGHSA enrichment
- 2026-08-26 04:28 UTCGHSA enrichment
Publicly available exploits
(9 references)Working exploit code is in the public domain (3 Metasploit modules) (5 GitHub PoCs). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
- GitHub PoCvonahisec/CVE-2022-47966-ScanFirst seen Jan 23, 2023
Python scanner for CVE-2022-47966. Supports ~10 of the 24 affected products.
Open source ↗ - GitHub PoCsh4den/CVE-2022-47966First seen Jan 23, 2023
The manage engine mass loader for CVE-2022-47966
Open source ↗ - GitHub PoCACE-Responder/CVE-2022-47966_checkerFirst seen Jan 23, 2023
Run on your ManageEngine server
Open source ↗ - GitHub PoCSystemVll/CVE-2022-47966First seen Jan 23, 2023
The manage engine mass loader for CVE-2022-47966
Open source ↗ - GitHub PoChorizon3ai/CVE-2022-47966First seen Jan 17, 2023
POC for CVE-2022-47966 affecting multiple ManageEngine products
Open source ↗ - Metasploitexploit/windows/http/manageengine_endpoint_central_saml_rce_cve_2022_47966✓ verifiedFirst seen Jan 10, 2023
ManageEngine Endpoint Central Unauthenticated SAML RCE
Open source ↗ - Metasploitexploit/multi/http/manageengine_adselfservice_plus_saml_rce_cve_2022_47966✓ verifiedFirst seen Jan 10, 2023
ManageEngine ADSelfService Plus Unauthenticated SAML RCE
Open source ↗ - Metasploitexploit/multi/http/manageengine_servicedesk_plus_saml_rce_cve_2022_47966✓ verifiedFirst seen Jan 10, 2023
ManageEngine ServiceDesk Plus Unauthenticated SAML RCE
Open source ↗ - Nucleihttp/cves/2022/CVE-2022-47966.yamlFirst seen Jan 1, 2022
ManageEngine - Remote Command Execution
Open source ↗
Related CVEs(same CWE)
Same CWE
10 shownCWE-20
- CVE-2005-0050EG 10.0EPSS p99HIGH
- CVE-2004-1019EG 10.0EPSS p94HIGH
- CVE-2004-0840EG 10.0EPSS p98HIGH
- CVE-2003-1425EG 10.0EPSS p96HIGH
- CVE-2003-1487EG 10.0EPSS p94HIGH
- CVE-2002-1874EG 10.0HIGH
- CVE-2002-2236EG 10.0EPSS p91HIGH
- CVE-2002-2365EG 10.0HIGH
- CVE-2002-1358EG 10.0EPSS p93HIGH
- CVE-2002-1359EG 10.0EPSS p100HIGH
Frequently asked(6)
What is CVE-2022-47966?
When was CVE-2022-47966 disclosed?
Is CVE-2022-47966 actively exploited?
What is the CVSS score of CVE-2022-47966?
Which products are affected by CVE-2022-47966?
How do I remediate CVE-2022-47966?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2022-47966
Is Your Infrastructure Affected by CVE-2022-47966?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.