CVE-2026-86677: Zohocorp ManageEngine Applications Manager

High severity, CVSS 8.8. EPSS: 2% chance of exploitation in the next 30 days.

ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to run unauthorized SQL commands, potentially gaining administrator access and remote code execution.

Affected products

  • Zohocorp ManageEngine Applications Manager: before 182100 (fixed in 182100)

Published 2026-09-23. Last modified 2026-09-24.