CVE-2020-10541: Zohocorp ManageEngine Opmanager

Critical severity, CVSS 9.8. EPSS: 10.1% chance of exploitation in the next 30 days.

Zoho ManageEngine OpManager before 12.4.179 allows remote code execution via a specially crafted Mail Server Settings v1 API request. This was fixed in 12.5.108.

Affected products

  • Zohocorp ManageEngine Opmanager: before 12.4.179 (fixed in 12.4.179)

Published 2020-03-13. Last modified 2026-06-17.