CVE-2026-12269: Zohocorp Ddi Central
High severity, CVSS 8.8. EPSS: 7% chance of exploitation in the next 30 days.
Zohocorp ManageEngine DDI Central 6.2.0 build below 6201 had a Keepalived configuration injection vulnerability in the HA configuration workflow. This issue could allow an authenticated operator-level user to modify the Keepalived configuration and potentially execute commands as root on the DDI Central host.
Affected products
- Zohocorp Ddi Central: before 6201 (fixed in 6201)
Published 2026-09-28. Last modified 2026-09-29.