Remote Code Execution Vulnerability in ZohoCorp ManageEngine OpManager MSP
CVE-2026-19599

9.9CRITICAL

Key Information:

Vendor

Zohocorp

Vendor
CVE Published:
23 September 2026

What is CVE-2026-19599?

In a recent security advisory, it was revealed that the Notification Profile module of ZohoCorp's ManageEngine OpManager MSP versions 12.8.709 and earlier is susceptible to a Remote Code Execution vulnerability. This flaw could potentially allow an attacker to execute arbitrary code on affected systems, posing a significant threat to the integrity and confidentiality of the data managed by these systems. Users of these versions are strongly encouraged to apply security updates and follow best practices to mitigate the risk associated with this vulnerability.

Affected Version(s)

ManageEngine OpManager 0 < 12.8.711

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.