Zoho ManageEngine: 20 Vulnerabilities Disclosed, Including Critical RCE and Auth Bypass
Key findings • 20 Zoho ManageEngine vulnerabilities disclosed Sept 23-24, 2026, spanning multiple products. • Critical flaws include RCE in ADSelfService Plus (CVE-2026-74849) and Application…

Key findings
- 20 Zoho ManageEngine vulnerabilities disclosed Sept 23-24, 2026, spanning multiple products.
- Critical flaws include RCE in ADSelfService Plus (CVE-2026-74849) and Applications Manager key exposure (CVE-2026-86708).
- High-severity issues include SQLi, command injection, auth bypass, and privilege escalation in OpManager and Applications Manager.
- Vulnerabilities range from DoS to RCE, impacting EventLog Analyzer, Log360, Applications Manager, OpManager, Firewall Analyzer, and ADSelfService Plus.
- Patches and updates are available; users urged to update immediately to mitigate risks.
On September 23-24, 2026, a significant batch of 20 vulnerabilities was disclosed across multiple Zoho ManageEngine products, including EventLog Analyzer, Log360, Applications Manager, OpManager, Firewall Analyzer, Network Configuration Manager, and ADSelfService Plus. The vulnerabilities, disclosed between September 22 and September 24, span a range of severities, with several critical and high-severity flaws posing substantial risks to organizations. These issues include remote code execution, SQL injection, command injection, authentication bypass, and denial-of-service vulnerabilities, underscoring the broad impact of this coordinated disclosure event.
A critical vulnerability in Zoho ManageEngine ADSelfService Plus, CVE-2026-74849, with a CVSS score of 9.8, allows for remote code execution through the GINA client. This flaw, affecting versions before build 7001, enables unauthenticated attackers to run code as SYSTEM through the Windows login screen, as reported by Cyber Security News. Another critical vulnerability, CVE-2026-86708 (CVSS 10.0), in Applications Manager (versions 182200 and below) involves the exposure of a Google Cloud service-account private key in the installer, potentially allowing impersonation and unauthorized access to cloud resources. Additionally, CVE-2026-19599 (CVSS 9.9) in OpManager MSP (versions 12.8.709 and below) presents a remote code execution risk in the Notification Profile module.
Several high-severity vulnerabilities were identified in ManageEngine Applications Manager. CVE-2026-86678 and CVE-2026-86677, both with CVSS 8.8, allow low-privileged users to obtain an administrator's API key or execute unauthorized SQL commands, respectively, potentially leading to administrator access and RCE. CVE-2026-86683 (CVSS 8.1) and CVE-2026-86679 (CVSS 7.1) involve a low-privileged user's ability to change proxy settings or delete service monitors outside their scope. CVE-2026-86681 (CVSS 7.6) permits low-privileged users to execute administrator-configured MBean actions on monitors outside their assigned scope.
ManageEngine OpManager and Firewall Analyzer are affected by a cluster of high-severity issues. CVE-2026-17487 (CVSS 8.8) is an SQL injection vulnerability in Rule Management Search Reports (versions 12.8.669 and below). CVE-2026-76978 (CVSS 8.8) allows command injection in the Diagnose Settings feature (versions 12.8.709 and below). CVE-2026-84787 (CVSS 8.1) is a privilege escalation vulnerability allowing low-privileged users to gain administrator privileges via Report Profile import (versions 12.8.710 and below). CVE-2026-76979 (CVSS 7.7) is an XML injection vulnerability in the Rule Tracking Compare Policies feature. CVE-2026-15358 (CVSS 7.5) involves an unauthorized path traversal vulnerability (versions before 12.8.671). CVE-2026-84791 (CVSS 7.1) and CVE-2026-84789 (CVSS 7.1) are broken access control vulnerabilities allowing low-privilege users to modify firewall report schedules or create alert notifications outside their scope, respectively (versions 12.8.710 and below). CVE-2026-76980 (CVSS 7.4) is a data exposure vulnerability in the Firewall Analyzer syslog collector.
Further vulnerabilities include CVE-2026-18258 (CVSS 8.8) in OpManager and Firewall Analyzer, allowing RCE via command injection in the Diagnose Settings feature. CVE-2026-75825 (CVSS 8.8) in OpManager with the Application Manager Plugin enabled bypasses authentication (versions 12.8.710 and below). CVE-2026-12370 (CVSS 7.6) in OpManager, NetFlow Analyzer, and Network Configuration Manager allows RCE via Server-Side Template Injection in Configlet processing (versions 12.8.667 and below). Finally, CVE-2026-92905 (CVSS 5.3), a medium-severity DoS vulnerability in EventLog Analyzer and Log360 (before build 13071), allows attackers to crash the log collector using malformed syslog packets.
The batch also includes CVE-2026-75791 (CVSS 8.6), an authentication bypass in ADSelfService Plus (before build 7001) via the REST API.
Zoho has released patches and updates for the affected products. Users are strongly advised to consult the specific advisories for each product and apply the necessary updates to mitigate these risks. For ADSelfService Plus, build 7001 addresses CVE-2026-74849 and CVE-2026-75791. Applications Manager versions 182201 and later, and 182001 and later, are recommended for CVE-2026-86708, CVE-2026-86683, CVE-2026-86681, CVE-2026-86679, CVE-2026-86678, and CVE-2026-86677. OpManager and Firewall Analyzer versions 12.8.710 and later address CVE-2026-76980, CVE-2026-76979, CVE-2026-76978, CVE-2026-75825, CVE-2026-84791, CVE-2026-84789, CVE-2026-84787, and CVE-2026-17487. For CVE-2026-19599, OpManager MSP versions 12.8.710 and later are recommended. Versions 12.8.671 and later fix CVE-2026-15358. Versions 12.8.668 and later fix CVE-2026-12370. EventLog Analyzer and Log360 build 13071 addresses CVE-2026-92905.
This extensive set of vulnerabilities highlights the importance of timely patching and security updates for Zoho ManageEngine products. Organizations relying on these tools should prioritize updating to the latest available versions to protect against potential exploitation, which could lead to significant data breaches, system compromise, and operational disruptions. The coordinated disclosure of these flaws emphasizes the ongoing efforts by security researchers to identify and report vulnerabilities, urging vendors and users alike to maintain robust security postures.