CVE-2026-84791: Zohocorp ManageEngine Firewall Analyzer

High severity, CVSS 7.1. EPSS: 0.6% chance of exploitation in the next 30 days.

ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to modify Change Management report schedule configurations for firewalls outside their assigned scope.

Affected products

  • Zohocorp ManageEngine Firewall Analyzer: before 12.8.711 (fixed in 12.8.711)
  • Zohocorp ManageEngine Opmanager: before 12.8.711 (fixed in 12.8.711)

Published 2026-09-23. Last modified 2026-09-23.