CVE-2026-86679: Zohocorp ManageEngine Applications Manager

High severity, CVSS 7.1. EPSS: 0.8% chance of exploitation in the next 30 days.

ZohoCorp ManageEngine Applications Manager versions 182000 and below were vulnerable to a permissions validation issue that allowed a low-privileged user to delete service monitors outside their assigned scope.

Affected products

  • Zohocorp ManageEngine Applications Manager: before 182100 (fixed in 182100)

Published 2026-09-23. Last modified 2026-09-23.