CVE-2026-19599: Zohocorp ManageEngine Opmanager

Critical severity, CVSS 9.9. EPSS: 2.9% chance of exploitation in the next 30 days.

ZohoCorp ManageEngine OpManager MSP versions 12.8.709 and below were vulnerable to a Remote Code Execution vulnerability in the Notification Profile module.

Affected products

  • Zohocorp ManageEngine Opmanager: before 12.8.711 (fixed in 12.8.711)

Published 2026-09-23. Last modified 2026-09-24.