PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-12268 Zohocorp CVE debrief

ManageEngine DDI Central versions below 6201 have a high-severity vulnerability allowing PowerShell command injection through Windows DNS SPF/TXT record push, potentially leading to remote code execution. This vulnerability, CVE-2026-12268, has a CVSS score of 8.8 and is classified as HIGH severity. Defenders and administrators of ManageEngine DDI Central, especially those with versions below 6201, should assess exposure and prioritize verification and potential patching. The vulnerability could allow attackers to execute PowerShell commands, potentially leading to remote code execution. It is essential to verify the version of ManageEngine DDI Central and assess exposure to this

Vendor
Zohocorp
Product
DDI Central
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-28
Original CVE updated
2026-09-28
Advisory published
2026-09-28
Advisory updated
2026-09-28

Who should care

Defenders and administrators of ManageEngine DDI Central, especially those with versions below 6201, should assess exposure and prioritize verification and potential patching.

Why it matters

CVE-2026-12268 is a high-severity vulnerability in ManageEngine DDI Central versions below 6201, allowing PowerShell command injection through Windows DNS SPF/TXT record push, potentially leading to remote code execution. Defenders and administrators should assess exposure, prioritize version verification and patching, and update incident response plans.

  • Potential remote code execution through PowerShell command injection
  • Need for version verification and potential patching
  • Possible impact on Windows DNS SPF/TXT record push functionality
  • Requirement for updated incident response plans

Technical summary

The ManageEngine DDI Central versions below 6201 are vulnerable to PowerShell command injection through Windows DNS SPF/TXT record push, potentially leading to remote code execution. The vulnerability has a CVSS score of 8.8 and is classified as HIGH severity.

Defensive priority

High priority for version verification and potential patching

Recommended defensive actions

  • Verify if the ManageEngine DDI Central version is below 6201
  • Assess exposure to Windows DNS SPF/TXT record push functionality
  • Monitor for potential patches or updates from ManageEngine
  • Review and update incident response plans for potential remote code execution

Evidence notes

The CVE record and NVD entry provide initial details on the vulnerability. However, further verification is needed to confirm affected versions, exploitation status, and remediation steps.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-12268 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-12268

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-12268 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-12268

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://www.manageengine.com/dns-dhcp-ipam/security-updates/security-updates.html

    0fc0942c-577d-436f-ae8e-945763c79b02

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.