ManageEngine RCE Flaw Enables SYSTEM Code Execution From Windows Login Screen
Critical RCE flaw in ManageEngine ADSelfService Plus allows unauthenticated SYSTEM-level code execution from the Windows logon screen, requiring physical access.
ManageEngine has patched a critical remote code execution vulnerability, CVE-2026-74849, in its ADSelfService Plus software. The flaw, with a CVSS score of 9.8, allows an unauthenticated attacker with physical access to a Windows device's logon screen to execute arbitrary code as the highly privileged NT AUTHORITY\SYSTEM user. The vulnerability exists in the GINA client component used for self-service password resets. Organizations are urged to update to build 7001 or later and restrict physical access to affected endpoints.