Hi there,
This security advisory is to let you know that an unauthenticated remote code execution vulnerability was identified in PAM360 Application Gateway. The vulnerability has been addressed, and the issue does not exist in the fixed version.
CVE ID : CVE-2026-84182
Severity : High
Product Name | Affected Version(s) | Fixed Version(s) | Fixed On |
PAM360 Application Gateway | Till 5510 | 5600 | 31st August, 2026 |
Impact:
The remote code execution vulnerability allows an unauthenticated adversary to execute arbitrary commands in PAM360 Application Gateway.
Applicability:
To determine whether your environment is affected by this vulnerability, log in to the PAM360 application and navigate to Admin >> PAM360 Gateways >> Application Gateway. If you have an active Application Gateway configured, you should upgrade to the latest PAM360 Application Gateway version to address the vulnerability.
Steps to Upgrade:
Download the latest upgrade pack from the following link:
PAM360 Application Gateway - https://www.manageengine.com/privileged-access-management/application-gateway/upgradepack.html
Apply the latest build to your existing product installation as per the upgrade pack instructions provided in the above links.
Please contact our product support team for further details at pam360-support@manageengine.com.