CVE-2026-12268: Zohocorp Ddi Central

High severity, CVSS 8.8. EPSS: 4.7% chance of exploitation in the next 30 days.

ManageEngine DDI Central versions below 6201 are vulnerable to PowerShell command injection in Windows DNS SPF/TXT record push leading to remote code execution.

Affected products

  • Zohocorp Ddi Central: before 6201 (fixed in 6201)

Published 2026-09-28. Last modified 2026-09-29.