Zohocorp ManageEngine ADSelfService Plus versions before 6524 are vulnerable to Multi Factor Authentication Bypass.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-3183 represents a critical authentication bypass vulnerability in Zoho's ManageEngine ADSelfService Plus, affecting versions prior to 6524. This vulnerability allows attackers to circumvent multi-factor authentication controls, a foundational security mechanism protecting user identity and access. Organizations using ADSelfService Plus for identity and access management are directly at risk, as successful exploitation could grant unauthorized access to sensitive systems and data without proper credential validation. The high CVSS score of 7.1 reflects the severity of authentication bypass vulnerabilities, which undermine the entire security posture of identity governance systems.
While this CVE currently maps to CWE-290 (Authentication Using a Known Password) rather than specific MITRE ATT&CK techniques, Casky's 754 mapped security skills enable detection of the attack patterns this vulnerability enables—particularly credential access and initial access techniques. Practitioners using Casky would identify suspicious authentication patterns such as successful logins that bypass expected MFA challenges, anomalous session creation without proper factor verification, or authentication logs showing MFA controls being circumvented. Claude's extended reasoning capability helps security teams correlate these findings with user behavior baselines and system configurations, detecting when attackers exploit this vulnerability to establish persistent access. Until patches are applied, practitioners should prioritize monitoring authentication events and implementing compensating controls around ADSelfService Plus deployments.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-3183. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation