TL;DR
Zoho Corporation patched six critical ManageEngine security vulnerabilities across its network monitoring portfolio. These severe flaws allow remote code execution and unauthorized command injection. Network administrators must upgrade OpManager and Applications Manager immediately to prevent system compromise.
- Total: 6 CVEs
- Severity: 2 Critical · 4 High
- Actively exploited: None confirmed
- Highest severity: 10.0 (Critical · CVSSv3) — CVE-2026-86708
- Action: Apply the latest security updates now
Track every Zoho CVE the moment it's exploited.
Get free email alertsNotable CVEs
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-86708 | 10 | CWE-321 | 182300 | Not exploited |
| CVE-2026-19599 | 9.9 | CWE-78 | 12.8.711 | Not exploited |
| CVE-2026-75825 | 8.8 | CWE-306 | 12.8.711 | Not exploited |
| CVE-2026-76978 | 8.8 | CWE-78 | 12.8.710 | Not exploited |
| CVE-2026-76979 | 7.7 | CWE-91 | 12.8.710 | Not exploited |
| CVE-2026-76980 | 7.4 | CWE-20 | 12.8.710 | Not exploited |
Why It Matters
ManageEngine software actively monitors critical infrastructure for tens of thousands of enterprise organizations. Therefore, ManageEngine security vulnerabilities present severe risks to global corporate networks. The most dangerous flaw earned a perfect CVSS score of 10.0. Another critical defect scored 9.9 for remote code execution.
If exploited, an attacker could hijack cloud resources or run unauthorized commands. Fortunately, researchers responsibly disclosed these OpManager vulnerabilities. Security teams have confirmed no active exploitation in the wild. Furthermore, researchers have not published any public proof-of-concept exploit code. However, delaying security updates leaves enterprise monitoring servers open to internal and external threats.
How The Attacks Work
These six security flaws encompass multiple attack vectors, from broken access controls to exposed cryptographic keys.
Remote Code Execution And Command Injection
The highest-rated OpManager defect, tracked as CVE-2026-19599, affects the MSP Central server. The official advisory states, “A Remote Code Execution vulnerability, exploitable by a customer administrator user on the MSP Central installed server, was identified in the Notification Profile module.” This broken access control allows attackers to execute arbitrary commands.
Additionally, the command injection flaw tracked as CVE-2026-76978 targets the Diagnose Settings feature. The vendor noted that “A command injection vulnerability in the Diagnose Settings feature allowed a crafted request parameter to inject arbitrary CLI commands into the authenticated firewall.” Consequently, a low-privilege user could compromise the monitored firewall. Other flaws involve XML injection in the Compare Policies tool and an authentication bypass in the APM Plugin.
Exposed Cloud Service Keys
The Applications Manager installer suffered from a critical data exposure issue. According to the security bulletin, “The Applications Manager installer included a Google Cloud service-account private key with broader-than-required permissions.” An unauthenticated attacker could extract this key from the public installer. They could then impersonate the service account and manipulate cloud resources.
Affected Versions
These ManageEngine security vulnerabilities affect multiple product lines. OpManager, OpManager Enterprise Edition, and OpManager Nexus are vulnerable up to version 12.9.122. OpManager MSP versions up to 12.9.122 also require updates. Furthermore, the exposed cloud key impacts Applications Manager versions 182200 and below.
Patch Or Mitigation Steps
System administrators must apply the latest service packs immediately. To resolve the OpManager vulnerabilities, download the appropriate upgrade packs from the official ManageEngine OpManager service packs portal. You must upgrade to version 12.8.710 or 12.9.124 depending on your specific release branch.
For the cloud key exposure, users must deploy the latest Applications Manager build. The vendor removed the excessive permissions and replaced the encrypted key. Review the Applications Manager security update page for complete installation instructions. Patching these monitoring tools ensures your network infrastructure remains secure against unauthorized access.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!