CVE-2026-76978
- EPSS 3.73%
- Veröffentlicht 23.09.2026 12:28:35
- Zuletzt bearbeitet 24.09.2026 04:17:59
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to a Command Injection vulnerability in the Diagnose Settings feature.
CVE-2026-76979
- EPSS 1.13%
- Veröffentlicht 23.09.2026 12:22:49
- Zuletzt bearbeitet 23.09.2026 18:17:31
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to an XML Injection vulnerability in the Rule Tracking Compare Policies feature.
CVE-2026-76980
- EPSS 0.39%
- Veröffentlicht 23.09.2026 12:08:24
- Zuletzt bearbeitet 23.09.2026 18:17:31
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to a Data Exposure vulnerability in the Firewall Analyzer syslog collector.
CVE-2026-84787
- EPSS 0.85%
- Veröffentlicht 23.09.2026 11:57:33
- Zuletzt bearbeitet 24.09.2026 04:18:02
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Privilege Escalation vulnerability that allowed an authenticated low-privilege user to gain Administrator privileges through Report Profile import.
CVE-2026-84789
- EPSS 0.6%
- Veröffentlicht 23.09.2026 11:51:43
- Zuletzt bearbeitet 23.09.2026 18:17:31
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to create alert notifications for firewalls outside their assi...
CVE-2026-84791
- EPSS 0.6%
- Veröffentlicht 23.09.2026 11:45:33
- Zuletzt bearbeitet 23.09.2026 18:17:31
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to modify Change Management report schedule configurations for...
CVE-2026-14913
- EPSS 0.97%
- Veröffentlicht 23.09.2026 11:28:25
- Zuletzt bearbeitet 24.09.2026 04:17:39
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.669 and below were vulnerable to an SQL Injection vulnerability in Rule Management Search Reports.
CVE-2023-47211
- EPSS 47.02%
- Veröffentlicht 08.01.2024 15:15:25
- Zuletzt bearbeitet 04.11.2025 19:16:06
A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A specially crafted HTTP request can lead to arbitrary file creation. An attacker can send a malicious MiB file to trigger this vulnerabilit...
CVE-2023-6105
- EPSS 0.69%
- Veröffentlicht 15.11.2023 21:15:08
- Zuletzt bearbeitet 13.02.2025 18:16:03
An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use t...
CVE-2022-37024
- EPSS 78.68%
- Veröffentlicht 10.08.2022 20:16:05
- Zuletzt bearbeitet 21.11.2024 07:14:18
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 2022-07-29 through 2022-07-30 ( 125658, 126003, 126105, and 126120) allow authenticated users to make database changes tha...