PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-3880 Zohocorp CVE debrief

CVE-2026-3880 is a Stored XSS vulnerability in Zohocorp ManageEngine Exchange Reporter Plus versions before 5802. The vulnerability exists in the Public Folder Client Permissions report. The CVSS score is 7.3, indicating a HIGH severity. This vulnerability allows an attacker to inject malicious code, which is then stored and executed when other users view the report. Administrators and users should be aware of this vulnerability and take necessary actions to mitigate it. The CVE record and NVD entry provide additional context.

Vendor
Zohocorp
Product
ManageEngine Exchange Reporter Plus
CVSS
HIGH 7.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-03
Original CVE updated
2026-07-24
Advisory published
2026-04-03
Advisory updated
2026-07-24

Who should care

Administrators and users of Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 should be aware of this vulnerability and take necessary actions to mitigate it. This includes updating to version 5802 or later, reviewing and limiting user permissions, and monitoring for suspicious activity. Security teams and vulnerability management teams should also be aware of this vulnerability and plan accordingly.

Technical summary

The vulnerability is a Stored XSS in the Public Folder Client Permissions report of Zohocorp ManageEngine Exchange Reporter Plus versions before 5802. This allows an attacker to inject malicious code, which is then stored and executed when other users view the report. The vulnerability has a CVSS score of 7.3, indicating a HIGH severity. The CVE record and NVD entry provide additional technical details.

Defensive priority

High priority should be given to updating Zohocorp ManageEngine Exchange Reporter Plus to version 5802 or later to mitigate this vulnerability. Additionally, reviewing and limiting user permissions, monitoring for suspicious activity, and checking relevant logs are also important defensive measures.

Recommended defensive actions

  • Update Zohocorp ManageEngine Exchange Reporter Plus to version 5802 or later
  • Review and limit user permissions to the Public Folder Client Permissions report
  • Monitor for suspicious activity in the Public Folder Client Permissions report
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record was published on 2026-04-03T12:16:18.933Z and last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Analyzed. The vulnerability is a Stored XSS in the Public Folder Client Permissions report of Zohocorp ManageEngine Exchange Reporter Plus versions before 5802. This information is based on the CVE record and NVD entry. Further verification is recommended to ensure accuracy.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-3880 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-3880

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-3880 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-3880

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://www.manageengine.com/products/exchange-reports/advisory/CVE-2026-3880.html

    0fc0942c-577d-436f-ae8e-945763c79b02 - Vendor Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.