securityonline.info 23 Sept 2026, 14:34 UTC

Zoho Fixes Critical ManageEngine Flaws Exposing Cloud Credentials

Zoho Fixes Critical ManageEngine Flaws Exposing Cloud Credentials
CyberSIXT Evidence Panel Source marked as original reporting

ZOHO Corporation has patched six security vulnerabilities in its ManageEngine network-monitoring products: two rated critical and four high. The most severe, CVE-2026-86708, has a CVSS v3 score of 10.0 and involves an exposed Google Cloud service-account private key in the Applications Manager installer. An unauthenticated attacker could extract the key, impersonate the service account and manipulate cloud resources. The article says no exploitation has been confirmed and no public proof-of-concept code has been released.

The other flaws include CVE-2026-19599, rated 9.9, a remote-code-execution issue in the MSP Central Notification Profile module that could be exploited by a customer administrator; and CVE-2026-76978, rated 8.8, a command-injection vulnerability in OpManager’s Diagnose Settings feature that could allow a low-privilege user to inject CLI commands into an authenticated firewall. The report also describes XML injection and authentication-bypass issues.

Affected OpManager, OpManager Enterprise Edition, OpManager Nexus and OpManager MSP versions include releases up to 12.9.122, while Applications Manager versions 182200 and earlier contain the exposed key.

Administrators are advised to apply the vendor’s service packs. Depending on the release branch, OpManager should be upgraded to version 12.8.710 or 12.9.124, while Applications Manager users should install the latest build, in which Zoho says it replaced the key and removed its excessive permissions.

View full article

Article by CyberSIXT