Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-19599: ManageEngine OpManager can be taken over via notifications

CVE-2026-19599 · published 2 days ago
Summary

Versions of ManageEngine OpManager up to 12.8.709 allow attackers to run their own code through the Notification Profile feature. This could let a malicious user gain control of the system and access sensitive data. Apply the latest security update or upgrade to a newer version as soon as possible.

What to do
  • Update zohocorp manageengine opmanager to version 12.8.711 or later.
Affected software
VendorProductAffected versions
zohocorp manageengine opmanager < 12.8.711
Original advisory text
Remote Code Execution vulnerability
ZohoCorp ManageEngine OpManager MSP versions 12.8.709 and below were vulnerable to a Remote Code Execution vulnerability in the Notification Profile module.
Severity
9.9 Critical
CVSS 3.1: 9.9 (MITRE)
Exploitation
EPSS 3%
Type
CWE-78OS Command Injection
Timeline
Published23 Sep 2026
Updated25 Sep 2026
First seen23 Sep 2026
Sources
CVE-2026-19599 · MITRE
Track software like this
Free during beta