PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-3880 Zohocorp CVE debrief

CVE-2026-3880 is a Stored XSS vulnerability in Zohocorp ManageEngine Exchange Reporter Plus versions before 5802. The vulnerability exists in the Public Folder Client Permissions report. The CVSS score is 7.3, indicating a HIGH severity. This vulnerability allows an attacker to inject malicious code, which is then stored and executed when other users view the report. Administrators and users should be aware of this vulnerability and take necessary actions to mitigate it. The CVE record and NVD entry provide additional context.

Vendor
Zohocorp
Product
ManageEngine Exchange Reporter Plus
CVSS
HIGH 7.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-03
Original CVE updated
2026-07-24
Advisory published
2026-04-03
Advisory updated
2026-07-24

Who should care

Administrators and users of Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 should be aware of this vulnerability and take necessary actions to mitigate it. This includes updating to version 5802 or later, reviewing and limiting user permissions, and monitoring for suspicious activity. Security teams and vulnerability management teams should also be aware of this vulnerability and plan accordingly.

Technical summary

The vulnerability is a Stored XSS in the Public Folder Client Permissions report of Zohocorp ManageEngine Exchange Reporter Plus versions before 5802. This allows an attacker to inject malicious code, which is then stored and executed when other users view the report. The vulnerability has a CVSS score of 7.3, indicating a HIGH severity. The CVE record and NVD entry provide additional technical details.

Defensive priority

High priority should be given to updating Zohocorp ManageEngine Exchange Reporter Plus to version 5802 or later to mitigate this vulnerability. Additionally, reviewing and limiting user permissions, monitoring for suspicious activity, and checking relevant logs are also important defensive measures.

Recommended defensive actions

  • Update Zohocorp ManageEngine Exchange Reporter Plus to version 5802 or later
  • Review and limit user permissions to the Public Folder Client Permissions report
  • Monitor for suspicious activity in the Public Folder Client Permissions report
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record was published on 2026-04-03T12:16:18.933Z and last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Analyzed. The vulnerability is a Stored XSS in the Public Folder Client Permissions report of Zohocorp ManageEngine Exchange Reporter Plus versions before 5802. This information is based on the CVE record and NVD entry. Further verification is recommended to ensure accuracy.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-03T12:16:18.933Z and has not been modified since then. The NVD entry is currently Analyzed.