CVE-2026-86678: Zohocorp ManageEngine Applications Manager
High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.
ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to obtain an administrator’s API key and use it to perform administrator-level actions.
Affected products
- Zohocorp ManageEngine Applications Manager: before 182100 (fixed in 182100)
Published 2026-09-23. Last modified 2026-09-24.