Data Exposure Vulnerability in ZohoCorp ManageEngine OpManager and Firewall Analyzer
CVE-2026-76980

7.4HIGH

Key Information:

Vendor

Zohocorp

Vendor
CVE Published:
23 September 2026

What is CVE-2026-76980?

ZohoCorp's ManageEngine OpManager and Firewall Analyzer, specifically versions 12.8.709 and earlier, have a vulnerability in the syslog collector that could lead to data exposure. This flaw allows unauthorized access to sensitive information, potentially compromising the security of users and systems. It is crucial for organizations utilizing these products to assess their current versions and apply necessary updates to mitigate the risk.

Affected Version(s)

ManageEngine Firewall Analyzer 0 < 12.8.710

ManageEngine OpManager 0 < 12.8.710

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.