CVE-2026-86678
- EPSS 0.68%
- Veröffentlicht 23.09.2026 13:41:27
- Zuletzt bearbeitet 24.09.2026 04:18:03
ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to obtain an administrator’s API key and use it to perform administrator-level actions.
CVE-2026-86677
- EPSS 2.02%
- Veröffentlicht 23.09.2026 13:36:03
- Zuletzt bearbeitet 24.09.2026 04:18:03
ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to run unauthorized SQL commands, potentially gaining administrator access and remote code execution.
CVE-2026-86679
- EPSS 0.78%
- Veröffentlicht 23.09.2026 13:29:51
- Zuletzt bearbeitet 23.09.2026 18:17:31
ZohoCorp ManageEngine Applications Manager versions 182000 and below were vulnerable to a permissions validation issue that allowed a low-privileged user to delete service monitors outside their assigned scope.
CVE-2026-86683
- EPSS 0.68%
- Veröffentlicht 23.09.2026 13:23:58
- Zuletzt bearbeitet 24.09.2026 04:18:03
ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to change the proxy settings.
CVE-2026-86681
- EPSS 0.46%
- Veröffentlicht 23.09.2026 13:17:16
- Zuletzt bearbeitet 23.09.2026 18:17:31
ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to a permissions validation issue that allowed low-privileged users to execute administrator-configured MBean actions on monitors outside their assigned scope.
- EPSS 1.24%
- Veröffentlicht 23.09.2026 13:11:31
- Zuletzt bearbeitet 24.09.2026 04:18:03
ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private key in the Applications Manager installer, which could allow an unauthenticated attacker to impersonate the ser...
CVE-2025-9787
- EPSS 1.08%
- Veröffentlicht 18.12.2025 14:14:52
- Zuletzt bearbeitet 30.09.2026 23:10:00
Zohocorp ManageEngine Applications Manager versions 177400 and below are vulnerable to Stored Cross-Site Scripting vulnerability in the NOC view.
CVE-2025-9223
- EPSS 4.24%
- Veröffentlicht 11.11.2025 13:13:24
- Zuletzt bearbeitet 26.09.2026 00:10:00
Zohocorp ManageEngine Applications Manager versions 178100 and below are vulnerable to authenticated command injection vulnerability due to the improper configuration in the execute program action feature.
CVE-2025-6239
- EPSS 0.89%
- Veröffentlicht 21.10.2025 12:25:21
- Zuletzt bearbeitet 24.10.2025 12:52:49
Zohocorp ManageEngine Applications Manager versions 176800 and below are vulnerable to information disclosure in File/Directory monitor.
CVE-2025-27930
- EPSS 0.41%
- Veröffentlicht 23.07.2025 10:20:09
- Zuletzt bearbeitet 30.09.2025 15:03:30
Zohocorp ManageEngine Applications Manager versions 176600 and prior are vulnerable to stored cross-site scripting in the File/Directory monitor.