CVE-2026-12263: Zohocorp ManageEngine PAM360
High severity, CVSS 8.8. EPSS: 1.4% chance of exploitation in the next 30 days.
Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SAML validation.
Affected products
- Zohocorp ManageEngine PAM360: before 8551 (fixed in 8551)
- Zohocorp ManageEngine Password Manager Pro: before 13232 (fixed in 13232)
Published 2026-08-13. Last modified 2026-08-31.