Critical ManageEngine RCE Flaw Allows SYSTEM Code Execution from Windows Login Screen
A critical RCE flaw (CVE-2026-74849) in ManageEngine ADSelfService Plus allows unauthenticated SYSTEM-level code execution from the Windows logon screen, requiring physical access to the device.
ManageEngine has patched a critical remote code execution vulnerability, CVE-2026-74849, in its ADSelfService Plus software. The flaw, which has a CVSS score of 9.8, exists in the GINA client component used for self-service password resets on the Windows login screen. It allows an unauthenticated attacker with physical access to a device to execute arbitrary code as the highly privileged SYSTEM user via OS command injection. Organizations are urged to update to build 7001 or later and restrict physical access to affected endpoints.
- CVE-2026-74849, a critical remote code execution (RCE) vulnerability in ManageEngine ADSelfService Plus, has a CVSS score of 9.8.
- The flaw exists in the GINA client component, which presents password reset functions on the Windows login screen.
- It allows an unauthenticated attacker to execute arbitrary commands as the SYSTEM user (NT AUTHORITY\SYSTEM).
- Exploitation requires physical access to a device's login screen.
- The root cause is OS command injection (CWE-78).
- The vulnerability affects builds 7000 and earlier.
- It is patched in build 7001, released on August 24, 2026.
Coverage timelineoldest first · each row is one article
- · 4d agoCritical ManageEngine Flaw Lets Attackers Gain SYSTEM Access Through Windows Login Screen
Cyber Security News· 65
Critical CVE-2026-74849 in ManageEngine ADSelfService Plus lets unauthenticated attackers execute SYSTEM code via the Windows login screen.
- · 3d agoManageEngine RCE Flaw Enables SYSTEM Code Execution From Windows Login Screen
GBHackers· 80
Critical RCE flaw in ManageEngine ADSelfService Plus allows unauthenticated SYSTEM-level code execution from the Windows logon screen, requiring physical access.
Vulnerabilities in this storyAll →
- CVE-2026-748499.8—Unauthenticated OS Command Injection RCE in ManageEngine ADSelfService Plus GINA Clientpublished · Zohocorp (ManageEngine) ManageEngine ADSelfService Plus (GINA client)
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-74849 | Unauthenticated OS Command Injection RCE in ManageEngine ADSelfService Plus GINA Client Zohocorp ManageEngine ADSelfService Plus builds before 7001 contain a remote code execution flaw, classified as OS command injection (CWE-78), in the GINA client component that provides Windows logon-screen self-service password reset and account unlock. The CVSS 3.1 score of 9.8 (network vector, low attack complexity, no privileges or user interaction required) indicates an unauthenticated remote attacker can exploit it over the network and fully compromise confidentiality, integrity, and availability of the affected machine. Organizations running older builds of ADSelfService Plus, especially those that have rolled the GINA client out to domain-joined Windows machines, are affected. There is no known public proof of concept, the flaw is not on the CISA Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported to date, but ManageEngine products have historically been targeted quickly once details circulate. |