CVE-2026-12269: Zohocorp Ddi Central

High severity, CVSS 8.8. EPSS: 7% chance of exploitation in the next 30 days.

Zohocorp ManageEngine DDI Central 6.2.0 build below 6201 had a Keepalived configuration injection vulnerability in the HA configuration workflow. This issue could allow an authenticated operator-level user to modify the Keepalived configuration and potentially execute commands as root on the DDI Central host.

Affected products

  • Zohocorp Ddi Central: before 6201 (fixed in 6201)

Published 2026-09-28. Last modified 2026-09-29.