These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-12269 is a high-severity vulnerability in Zohocorp ManageEngine DDI Central 6.2.0 build below 6201, allowing an authenticated operator-level user to modify the Keepalived configuration and potentially execute commands as root on the DDI Central host. This issue arises from inadequate validation of user input in the HA configuration workflow, which could lead to privilege escalation. Defenders sho [truncated]
ManageEngine DDI Central versions below 6201 have a high-severity vulnerability allowing PowerShell command injection through Windows DNS SPF/TXT record push, potentially leading to remote code execution. This vulnerability, CVE-2026-12268, has a CVSS score of 8.8 and is classified as HIGH severity. Defenders and administrators of ManageEngine DDI Central, especially those with versions below 6201, should [truncated]
ManageEngine DDI Central versions below 6201 have a command injection vulnerability in the Windows DNS Query Resolution Policy name field. This could potentially lead to remote code execution. Defenders should verify exposure and prioritize patching or mitigation. The vulnerability exists due to insufficient validation of user input in the affected field, allowing attackers to inject malicious commands. I [truncated]
CVE-2026-85640 debrief based on the supplied source corpus. The CVE record was published on 2026-09-07T11:17:37.613Z and has not been modified since then. This medium-severity vulnerability in ManageEngine Endpoint Central versions below 11.5.2600.15 allows for privilege escalation due to an outdated component. IT administrators and security teams should assess exposure and prioritize patching to prevent [truncated]
CVE-2026-77699 is a local privilege escalation vulnerability in Zohocorp ManageEngine Endpoint Central versions below 11.5.2605.01. The vulnerability is caused by loading a DLL from an untrusted path. This could allow an attacker to escalate privileges on the system. Defenders responsible for managing and securing Zohocorp ManageEngine Endpoint Central installations should assess exposure and prioritize v [truncated]
CVE-2026-77697 is a Privilege Escalation During JAR Extraction vulnerability affecting Zohocorp ManageEngine Endpoint Central versions below 11.4.2540.23. The vulnerability has a CVSS score of 6.3 and a severity of MEDIUM. According to the CVE Program and NVD, the vulnerability was published on 2026-09-07T11:17:35.687Z and has not been modified since then.
CVE-2026-77698 is a local privilege escalation vulnerability affecting Zohocorp ManageEngine Endpoint Central versions before 11.5.2605.01 due to Agent upgrade. The CVE record was published on 2026-09-07T10:16:53.673Z and has not been modified since then. The NVD entry is currently Received. Defenders responsible for managing and securing Zohocorp ManageEngine Endpoint Central installations should assess [truncated]
CVE-2026-14828 is an authenticated SQL Injection vulnerability affecting Zohocorp ManageEngine Password Manager Pro, PAM360, and Access Manager Plus. Defenders should assess exposure, prioritize remediation, and verify vendor-provided fixes. The vulnerability allows an authenticated attacker to inject malicious SQL, potentially leading to data breaches and unauthorized access. Defenders must review vendor [truncated]
CVE-2026-12263 is an authentication bypass vulnerability in Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 due to improper SAML validation. The vulnerability has a CVSS score of 8.8 and is classified as HIGH severity. Organizations using these products should be aware of the potential for authentication bypass attacks and take steps to patch or mitigate th [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T08:16:42.987Z and has not been modified since then. CVE-2026-11840 is an authenticated SQL injection vulnerability affecting Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions before 8552. The vulnerability has a CVSS score of 8.8 and is classified a [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-11T17:17:46.940Z and has not been modified since then. CVE-2026-12571 is an authentication bypass vulnerability in ManageEngine DDI Central's password-reset workflow, allowing account takeover with a CVSS score of 9.8, indicating critical severity. Organizations using ManageEngine DDI Central should [truncated]
CVE-2026-11374 is a critical vulnerability in ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus. The issue allows an unauthenticated user to predict SSO tickets, potentially leading to account takeover. The vulnerability has a CVSS score of 9 and is considered critical. ManageEngine has released an advisory for this vulnerability. Users of these products should rev [truncated]
The Zoho Mail WordPress plugin contains a Cross-Site Request Forgery (CSRF) vulnerability in versions prior to 1.6.2. CSRF flaws allow attackers to trick authenticated users into performing unintended actions by submitting malicious requests using the victim's established session. The vulnerability is classified as MEDIUM severity with a CVSS 3.1 score of 5.7, indicating moderate risk with network attack [truncated]
CVE-2026-2740 is a high-severity authenticated remote code execution issue affecting ManageEngine ADSelfService Plus before 6525, DataSecurity Plus before 6264, and RecoveryManager Plus before 6313. The supplied NVD record rates it 8.4 and maps it to CWE-77, with a CVSS 3.1 vector of AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L, indicating network-reachable impact that requires authenticated access and high attack complexity.
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-16T15:17:38.010Z and has not been modified since then. Zohocorp ManageEngine Log360 versions 13000 through 13013 are vulnerable to authentication bypass on certain actions due to improper filter configuration. This vulnerability allows attackers to bypass authentication mechanisms, potentially leadi [truncated]
CVE-2026-27655 is a Stored XSS vulnerability in the Permissions Based on Mailboxes report of Zohocorp ManageEngine Exchange Reporter Plus versions before 5802. This vulnerability allows for Stored XSS attacks, posing a High severity threat with a CVSS score of 7.3. Users of affected versions should apply patches immediately to prevent exploitation.
CVE-2026-4108 is a Stored XSS vulnerability in Zohocorp ManageEngine Exchange Reporter Plus versions before 5802, affecting the Non-Owner Mailbox Permission report. The CVE record was published on 2026-04-03T12:16:19.207Z and was last modified on 2026-07-24T21:10:00.143Z. This vulnerability allows for Stored XSS in the Non-Owner Mailbox Permission report of ManageEngine Exchange Reporter Plus versions bef [truncated]
CVE-2026-4107 is a Stored XSS vulnerability in the Folder Message Count and Size report of Zohocorp ManageEngine Exchange Reporter Plus versions before 5802. This vulnerability could allow an attacker to inject malicious scripts into the report, potentially leading to unauthorized actions or data breaches. Users of affected versions should prioritize patching to prevent exploitation. The Common Vulnerabil [truncated]
CVE-2026-3880 is a Stored XSS vulnerability in Zohocorp ManageEngine Exchange Reporter Plus versions before 5802. The vulnerability exists in the Public Folder Client Permissions report. The CVSS score is 7.3, indicating a HIGH severity. This vulnerability allows an attacker to inject malicious code, which is then stored and executed when other users view the report. Administrators and users should be awa [truncated]
CVE-2026-3879 is a Stored XSS vulnerability in Zohocorp ManageEngine Exchange Reporter Plus versions before 5802. The vulnerability exists in the Equipment Mailbox Details report, allowing attackers to inject malicious scripts. This could lead to potential XSS attacks, impacting the security of the system. The CVSS score of 7.3 indicates a HIGH severity, emphasizing the need for prompt patching. Security [truncated]
CVE-2026-28703 is a Stored XSS vulnerability in ManageEngine Exchange Reporter Plus versions before 5802. The vulnerability is located in the Mails Exchanged Between Users report. This issue has a high CVSS score of 7.3, indicating high severity. Users of ManageEngine Exchange Reporter Plus versions before 5802 should apply the patch to prevent exploitation and review their inventory of instances.
CVE-2026-28756 is a Stored XSS vulnerability in the Permissions based on Distribution Groups report of Zohocorp ManageEngine Exchange Reporter Plus versions before 5802. The vulnerability has a CVSS score of 7.3 and is classified as HIGH severity. It allows an attacker to inject malicious scripts, potentially leading to unauthorized actions or data breaches. Administrators and users should be aware of thi [truncated]
CVE-2026-28754 is a Stored XSS vulnerability in the Distribution Lists report of Zohocorp ManageEngine Exchange Reporter Plus versions before 5802. This vulnerability allows an attacker to inject malicious scripts, potentially leading to unauthorized actions or data exposure. The vulnerability has a HIGH CVSS score of 7.3, indicating a high severity. Users of affected versions should apply the patch to pr [truncated]
CVE-2016-6603 is a critical remote authentication bypass in ZOHO WebNMS Framework 5.2 and 5.2 SP1. The flaw allows an unauthenticated attacker to impersonate arbitrary users by sending a crafted UserName HTTP header. NVD rates the issue 9.8/CRITICAL, consistent with network reachability, no required privileges, no user interaction, and high impact to confidentiality, integrity, and availability.
CVE-2016-6602 affects ZOHO WebNMS Framework 5.2 and 5.2 SP1. The issue is a weak password obfuscation design that can let a context-dependent attacker recover cleartext credentials from WEB-INF/conf/securitydbData.xml. NVD rates the issue critical and maps it to CWE-327; it also notes the flaw can be combined with CVE-2016-6601 for remote exploitation.
CVE-2016-6601 describes a directory traversal issue in the file download feature of ZOHO WebNMS Framework 5.2 and 5.2 SP1. The NVD record states that a remote attacker can supply path traversal sequences in the fileName parameter to servlets/FetchFile to read arbitrary files. Because the issue is network-reachable, requires no authentication, and exposes file contents, it is a high-priority confidentialit [truncated]
CVE-2016-6600 is a critical directory traversal flaw in ZOHO WebNMS Framework file upload handling. According to the supplied NVD record, the issue affects WebNMS Framework 5.2 and 5.2 SP1 and can allow remote attackers to upload and execute arbitrary JSP files through the fileName parameter in servlets/FileUploadServlet.