A serious security vulnerability has been identified in ManageEngine Exchange Reporter Plus, which could allow attackers to execute arbitrary commands on targeted servers.
See also: Critical vulnerability in Roundcube allows RCE execution

The vulnerability, codenamed CVE-2025-3835 , affects all versions of Exchange Reporter Plus with build 5721 and lower. ManageEngine responded immediately, releasing a patch in build 5722 on May 29, 2025. Cybersecurity experts urge all organizations using the affected version to update immediately, as exploiting the vulnerability could lead to a complete system breach and potential data leaks in corporate environments
The vulnerability, identified as CVE-2025-3835, specifically targets the content search module within ManageEngine Exchange Reporter Plus. This critical vulnerability could allow malicious actors to inject and execute unauthorized code on systems running the affected versions of the software.
The Content Search component, which is designed to help administrators search for Exchange Server content, contains a login validation flaw that fails to properly sanitize user-supplied parameters. This vulnerability represents a particularly dangerous attack vector because it could potentially grant attackers system-level privileges on compromised servers.
See also: RD Gateway UAF vulnerability allows RCE

The technical exploitation methodology involves sending specially crafted HTTP requests to the vulnerable Content Search endpoint. Once successfully exploited, attackers can execute arbitrary system commands. When executed, this payload bypasses login validation controls and runs with the same privileges as the Exchange Reporter Plus service account, which typically has elevated system privileges.
This vulnerability is rated critical due to the potential for a complete system compromise. Once exploited, attackers could execute arbitrary code with the same privileges as the account . This could allow threat actors to establish persistent access, move laterally within networks, extract sensitive data, or deploy additional malicious payloads such as ransomware.
See also: Asus DriverHub flaws lead to RCE attacks
The vulnerability in ManageEngine Exchange Reporter Plus was responsibly disclosed by security researcher Ngockhanhc311 from FPT NightWolf, demonstrating the importance of collaborative security research to identify and address critical vulnerabilities before widespread exploitation.
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
