CVE-2025-41437: ManageEngine Opmanager
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Zohocorp ManageEngine OpManager, NetFlow Analyzer, Network Configuration Manager, Firewall Analyzer and OpUtils versions 128565 and below are vulnerable to Reflected XSS on the login page.
Affected products
- ManageEngine Opmanager: before 128566 (fixed in 128566)
Published 2025-06-09. Last modified 2026-06-17.