PatchSiren cyber security CVE debrief
CVE-2026-3880 Zohocorp CVE debrief
CVE-2026-3880 is a Stored XSS vulnerability in Zohocorp ManageEngine Exchange Reporter Plus versions before 5802. The vulnerability exists in the Public Folder Client Permissions report. The CVSS score is 7.3, indicating a HIGH severity. This vulnerability allows an attacker to inject malicious code, which is then stored and executed when other users view the report. Administrators and users should be aware of this vulnerability and take necessary actions to mitigate it. The CVE record and NVD entry provide additional context.
- Vendor
- Zohocorp
- Product
- ManageEngine Exchange Reporter Plus
- CVSS
- HIGH 7.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-03
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-03
- Advisory updated
- 2026-07-24
Who should care
Administrators and users of Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 should be aware of this vulnerability and take necessary actions to mitigate it. This includes updating to version 5802 or later, reviewing and limiting user permissions, and monitoring for suspicious activity. Security teams and vulnerability management teams should also be aware of this vulnerability and plan accordingly.
Technical summary
The vulnerability is a Stored XSS in the Public Folder Client Permissions report of Zohocorp ManageEngine Exchange Reporter Plus versions before 5802. This allows an attacker to inject malicious code, which is then stored and executed when other users view the report. The vulnerability has a CVSS score of 7.3, indicating a HIGH severity. The CVE record and NVD entry provide additional technical details.
Defensive priority
High priority should be given to updating Zohocorp ManageEngine Exchange Reporter Plus to version 5802 or later to mitigate this vulnerability. Additionally, reviewing and limiting user permissions, monitoring for suspicious activity, and checking relevant logs are also important defensive measures.
Recommended defensive actions
- Update Zohocorp ManageEngine Exchange Reporter Plus to version 5802 or later
- Review and limit user permissions to the Public Folder Client Permissions report
- Monitor for suspicious activity in the Public Folder Client Permissions report
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record was published on 2026-04-03T12:16:18.933Z and last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Analyzed. The vulnerability is a Stored XSS in the Public Folder Client Permissions report of Zohocorp ManageEngine Exchange Reporter Plus versions before 5802. This information is based on the CVE record and NVD entry. Further verification is recommended to ensure accuracy.
Official resources
-
CVE-2026-3880 CVE record
CVE.org
-
CVE-2026-3880 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
0fc0942c-577d-436f-ae8e-945763c79b02 - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-03T12:16:18.933Z and has not been modified since then. The NVD entry is currently Analyzed.