CVE-2026-86681: Zohocorp ManageEngine Applications Manager

High severity, CVSS 7.6. EPSS: 0.5% chance of exploitation in the next 30 days.

ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to a permissions validation issue that allowed low-privileged users to execute administrator-configured MBean actions on monitors outside their assigned scope.

Affected products

  • Zohocorp ManageEngine Applications Manager: before 182300 (fixed in 182300)

Published 2026-09-23. Last modified 2026-09-23.