CVE-2026-15358: Zohocorp ManageEngine Network Configuration Manager

High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.

ZohoCorp ManageEngine OpManager and Network Configuration Manager versions before 12.8.671 were vulnerable to an unauthorized Path Traversal vulnerability.

Affected products

  • Zohocorp ManageEngine Network Configuration Manager: before 12.8.671 (fixed in 12.8.671)
  • Zohocorp ManageEngine Opmanager: before 12.8.671 (fixed in 12.8.671)

Published 2026-09-23. Last modified 2026-09-23.