CVE-2026-77697
- EPSS 0.25%
- Veröffentlicht 07.09.2026 10:49:52
- Zuletzt bearbeitet 08.09.2026 18:35:10
Zohocorp ManageEngine Endpoint Central versions below 11.4.2540.23 are vulnerable to Privilege Escalation During JAR Extraction
CVE-2026-85640
- EPSS 0.2%
- Veröffentlicht 07.09.2026 10:45:14
- Zuletzt bearbeitet 08.09.2026 18:35:10
Zohocorp ManageEngine Endpoint Central versions below 11.5.2600.15 are vulnerable to Privilege Escalation Due to Outdated Component
- EPSS 0.16%
- Veröffentlicht 07.09.2026 10:30:16
- Zuletzt bearbeitet 08.09.2026 18:35:10
Zohocorp ManageEngine Endpoint Central versions below 11.5.2605.01 are vulnerable to Local privilege escalation due to loading a dll from an untrusted path.
CVE-2026-77698
- EPSS 0.23%
- Veröffentlicht 07.09.2026 09:51:04
- Zuletzt bearbeitet 08.09.2026 18:35:10
Zohocorp ManageEngine Endpoint Central versions before 11.5.2605.01 are vulnerable to local privilege escalation due to Agent upgrade.
CVE-2026-3182
- EPSS 0.28%
- Veröffentlicht 21.07.2026 05:30:33
- Zuletzt bearbeitet 21.07.2026 18:34:20
Zohocorp ManageEngine Endpoint Central versions before 11.4.2528.34 are affected by cleartext transmission of sensitive information vulnerability.
CVE-2025-11248
- EPSS 0.48%
- Veröffentlicht 27.10.2025 13:15:42
- Zuletzt bearbeitet 28.10.2025 13:22:12
ZohoCorp ManageEngine Endpoint Central versions prior to 11.4.2528.05 are vulnerable to a sensitive information logging issue. An authenticated user with access to the logs could potentially obtain the sensitive agent token.
CVE-2025-7473
- EPSS 0.32%
- Veröffentlicht 21.10.2025 10:58:47
- Zuletzt bearbeitet 23.10.2025 14:36:06
Zohocorp ManageEngine EndPoint Central versions 11.4.2516.1 and prior are vulnerable to XML Injection.
CVE-2025-5496
- EPSS 0.24%
- Veröffentlicht 21.10.2025 10:15:34
- Zuletzt bearbeitet 28.10.2025 15:36:52
ZohoCorp ManageEngine Endpoint Central versions earlier than 11.4.2508.14, 11.4.2516.06, and 11.4.2518.01 are affected by an arbitrary file deletion vulnerability in the agent setup component.
CVE-2025-5494
- EPSS 0.25%
- Veröffentlicht 25.09.2025 14:15:46
- Zuletzt bearbeitet 22.10.2025 19:42:49
ZohoCorp ManageEngine Endpoint Central was impacted by an improper privilege management issue in the agent setup. This issue affects Endpoint Central: through 11.4.2500.25, through 11.4.2508.13.
CVE-2024-9097
- EPSS 0.62%
- Veröffentlicht 05.02.2025 13:15:23
- Zuletzt bearbeitet 22.10.2025 20:27:48
ManageEngine Endpoint Central versions before 11.3.2440.09 are vulnerable to IDOR vulnerability which allows the attacker to change the username in the chat.