PatchSiren cyber security CVE debrief
CVE-2026-12268 Zohocorp CVE debrief
ManageEngine DDI Central versions below 6201 have a high-severity vulnerability allowing PowerShell command injection through Windows DNS SPF/TXT record push, potentially leading to remote code execution. This vulnerability, CVE-2026-12268, has a CVSS score of 8.8 and is classified as HIGH severity. Defenders and administrators of ManageEngine DDI Central, especially those with versions below 6201, should assess exposure and prioritize verification and potential patching. The vulnerability could allow attackers to execute PowerShell commands, potentially leading to remote code execution. It is essential to verify the version of ManageEngine DDI Central and assess exposure to this
- Vendor
- Zohocorp
- Product
- DDI Central
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-28
- Original CVE updated
- 2026-09-28
- Advisory published
- 2026-09-28
- Advisory updated
- 2026-09-28
Who should care
Defenders and administrators of ManageEngine DDI Central, especially those with versions below 6201, should assess exposure and prioritize verification and potential patching.
Why it matters
CVE-2026-12268 is a high-severity vulnerability in ManageEngine DDI Central versions below 6201, allowing PowerShell command injection through Windows DNS SPF/TXT record push, potentially leading to remote code execution. Defenders and administrators should assess exposure, prioritize version verification and patching, and update incident response plans.
- Potential remote code execution through PowerShell command injection
- Need for version verification and potential patching
- Possible impact on Windows DNS SPF/TXT record push functionality
- Requirement for updated incident response plans
Technical summary
The ManageEngine DDI Central versions below 6201 are vulnerable to PowerShell command injection through Windows DNS SPF/TXT record push, potentially leading to remote code execution. The vulnerability has a CVSS score of 8.8 and is classified as HIGH severity.
Defensive priority
High priority for version verification and potential patching
Recommended defensive actions
- Verify if the ManageEngine DDI Central version is below 6201
- Assess exposure to Windows DNS SPF/TXT record push functionality
- Monitor for potential patches or updates from ManageEngine
- Review and update incident response plans for potential remote code execution
Evidence notes
The CVE record and NVD entry provide initial details on the vulnerability. However, further verification is needed to confirm affected versions, exploitation status, and remediation steps.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-12268 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-12268
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-12268 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-12268
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.manageengine.com/dns-dhcp-ipam/security-updates/security-updates.html
0fc0942c-577d-436f-ae8e-945763c79b02
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.