Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-86708: ManageEngine Applications Manager may leak Google Cloud key
CVE-2026-86708 · published 2 days ago
Summary
Versions 182200 and earlier of ManageEngine Applications Manager can unintentionally include a Google Cloud service‑account private key in the installation package. If someone obtains this key, they could pretend to be the service account and access or change cloud resources without permission. Update to a newer version or reinstall with the corrected installer to eliminate the risk.
What to do
- Update zohocorp manageengine applications manager to version 182300 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| zohocorp | manageengine applications manager | < 182300 |
Original advisory text
Sensitive data exposure
ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private key in the Applications Manager installer, which could allow an unauthenticated attacker to impersonate the service account and access or modify associated cloud resources.
Severity
10.0
Critical
CVSS 3.1: 10.0 (NVD)
Exploitation
EPSS 1%
Type
CWE-321Use of Hard-coded Cryptographic Key
Timeline
Published23 Sep 2026
Updated25 Sep 2026
First seen23 Sep 2026
Track software like this
Free during beta