Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-19599: ManageEngine OpManager can be taken over via notifications
CVE-2026-19599 · published 2 days ago
Summary
Versions of ManageEngine OpManager up to 12.8.709 allow attackers to run their own code through the Notification Profile feature. This could let a malicious user gain control of the system and access sensitive data. Apply the latest security update or upgrade to a newer version as soon as possible.
What to do
- Update zohocorp manageengine opmanager to version 12.8.711 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| zohocorp | manageengine opmanager | < 12.8.711 |
Original advisory text
Remote Code Execution vulnerability
ZohoCorp ManageEngine OpManager MSP versions 12.8.709 and below were vulnerable to a Remote Code Execution vulnerability in the Notification Profile module.
Severity
9.9
Critical
CVSS 3.1: 9.9 (MITRE)
Exploitation
EPSS 3%
Type
CWE-78OS Command Injection
Timeline
Published23 Sep 2026
Updated25 Sep 2026
First seen23 Sep 2026
Track software like this
Free during beta