Zoho Corp Zoho Corp ZoHo

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Zoho Corp product.

RSS Feeds for Zoho Corp security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Zoho Corp products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Zoho Corp Sorted by Most Security Vulnerabilities since 2018

Zoho Corp Manageengine Pam36018 vulnerabilities

Zoho Corp Manageengine Log36010 vulnerabilities

Zoho Corp Endpoint Central3 vulnerabilities

Zoho Corp Zoho Forms2 vulnerabilities

Zoho Corp Analytics Plus1 vulnerability

By the Year

In 2026 there have been 52 vulnerabilities in Zoho Corp with an average score of 7.7 out of ten. Last year, in 2025 Zoho Corp had 31 security vulnerabilities published. That is, 21 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 1.31.




Year Vulnerabilities Average Score
2026 52 7.71
2025 31 6.40
2024 53 8.10
2023 46 6.91
2022 55 7.67
2021 96 8.63
2020 40 7.72
2019 58 7.53
2018 48 7.76

It may take a day or so for new Zoho Corp vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Zoho Corp Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-92905 Sep 24, 2026
Zoho ManageEngine EventLog Analyzer DoS via malformed syslog packets ZohoCorp ManageEngine EventLog Analyzer and Log360 before build 13071 were vulnerable to a DoS vulnerability that allowed attackers to crash the log collector using malformed syslog packets.
Manageengine Eventlog Analyzer
Manageengine Log360
CVE-2026-86678 Sep 23, 2026
ZohoCorp ManageEngine Applications Manager versions 182000 and below ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to obtain an administrators API key and use it to perform administrator-level actions.
Manageengine Applications Manager
CVE-2026-86677 Sep 23, 2026
ZohoCorp ManageEngine Applications Manager versions 182000 and below ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to run unauthorized SQL commands, potentially gaining administrator access and remote code execution.
Manageengine Applications Manager
CVE-2026-86679 Sep 23, 2026
ZohoCorp ManageEngine Applications Manager versions 182000 and below were vulnerable to a permissions validation issue ZohoCorp ManageEngine Applications Manager versions 182000 and below were vulnerable to a permissions validation issue that allowed a low-privileged user to delete service monitors outside their assigned scope.
Manageengine Applications Manager
CVE-2026-86683 Sep 23, 2026
ZohoCorp ManageEngine Applications Manager versions 182000 and below ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to change the proxy settings.
Manageengine Applications Manager
CVE-2026-86681 Sep 23, 2026
ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to a permissions validation issue ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to a permissions validation issue that allowed low-privileged users to execute administrator-configured MBean actions on monitors outside their assigned scope.
Manageengine Applications Manager
CVE-2026-86708 Sep 23, 2026
ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private key in the Applications Manager installer, which could ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private key in the Applications Manager installer, which could allow an unauthenticated attacker to impersonate the service account and access or modify associated cloud resources.
Manageengine Applications Manager
CVE-2026-19599 Sep 23, 2026
RCE in Zoho ManageEngine OpManager MSP <=12.8.709 Notification Profile ZohoCorp ManageEngine OpManager MSP versions 12.8.709 and below were vulnerable to a Remote Code Execution vulnerability in the Notification Profile module.
Manageengine Opmanager
CVE-2026-75825 Sep 23, 2026
Auth Bypass in ZohoCorp ManageEngine OpManager <12.8.710 with AppMgr Plugin ZohoCorp ManageEngine OpManager versions 12.8.710 and below with the Application Manager Plugin enabled were vulnerable to an Authentication Bypass vulnerability.
Manageengine Opmanager
CVE-2026-76978 Sep 23, 2026
Zoho ManageEngine OpManager <12.8.709: Cmd Injection via Diagnose Settings ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to a Command Injection vulnerability in the Diagnose Settings feature.
Manageengine Opmanager
Manageengine Firewall Analyzer
CVE-2026-76979 Sep 23, 2026
XML Injection in ZohoCorp OpManager <=12.8.709 ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to an XML Injection vulnerability in the Rule Tracking Compare Policies feature.
Manageengine Opmanager
Manageengine Firewall Analyzer
CVE-2026-76980 Sep 23, 2026
Data Exposure in ManageEngine Firewall Analyzer Syslog Collector 12.8.709 ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to a Data Exposure vulnerability in the Firewall Analyzer syslog collector.
Manageengine Opmanager
Manageengine Firewall Analyzer
CVE-2026-84787 Sep 23, 2026
ZohoCorp OpMgr & FW Analyzer <12.8.710 Priv Esc via Report Profile Import ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Privilege Escalation vulnerability that allowed an authenticated low-privilege user to gain Administrator privileges through Report Profile import.
Manageengine Opmanager
Manageengine Firewall Analyzer
CVE-2026-84789 Sep 23, 2026
OpManager/Firewall Analyzer <=12.8.710: Broken Control - Unauthorized Alerts ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to create alert notifications for firewalls outside their assigned scope.
Manageengine Opmanager
Manageengine Firewall Analyzer
CVE-2026-84791 Sep 23, 2026
OpMgr <12.8.710: Broken AC Change Report Schedules ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to modify Change Management report schedule configurations for firewalls outside their assigned scope.
Manageengine Opmanager
Manageengine Firewall Analyzer
CVE-2026-15358 Sep 23, 2026
OpManager & Net Config Manager <12.8.671 Path Traversal Vulnerability ZohoCorp ManageEngine OpManager and Network Configuration Manager versions before 12.8.671 were vulnerable to an unauthorized Path Traversal vulnerability.
Manageengine Opmanager
Manageengine Network Configuration Manager
CVE-2026-14913 Sep 23, 2026
ZohoCorp ManageEngine OpManager <=12.8.669 SQLi in Rule Mgmt Search Reports ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.669 and below were vulnerable to an SQL Injection vulnerability in Rule Management Search Reports.
Manageengine Opmanager
Manageengine Firewall Analyzer
CVE-2026-12370 Sep 23, 2026
ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.667 and below were vulnerable to a Server-Side Template Injection vulnerability in Configlet processing ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.667 and below were vulnerable to a Server-Side Template Injection vulnerability in Configlet processing, which could lead to Remote Code Execution.
Manageengine Opmanager
Manageengine Netflow Analyzer
Manageengine Network Configuration Manager
And others...
CVE-2026-75791 Sep 22, 2026
Zohocorp ADSelfService Plus REST API Auth Bypass Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to an authentication bypass vulnerability in the REST API.
Manageengine Adselfservice Plus
CVE-2026-74849 Sep 22, 2026
Remote Code Execution via GINA Client in ManageEngine ADSelfService Plus Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to a remote code execution vulnerability in the GINA client.
Manageengine Adselfservice Plus
CVE-2026-18912 Sep 18, 2026
Auth SQLi in ManageEngine DataSecurity Plus Reports Module ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allowing an authenticated technician to execute arbitrary SQL queries through the Reports module.
Manageengine Datasecurity Plus
CVE-2026-18911 Sep 18, 2026
DataSecurity Plus Agent Auth Bypass Pre6310 ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolled agents to send requests without proper authentication.
Manageengine Datasecurity Plus
CVE-2026-77697 Sep 07, 2026
PrivEsc Vulnerability in Zohocorp Endpoint Central <11.4.2540.23 via JAR Zohocorp ManageEngine Endpoint Central versions below 11.4.2540.23 are vulnerable to Privilege Escalation During JAR Extraction
Manageengine Endpoint Central
CVE-2026-85640 Sep 07, 2026
ManageEngine Endpoint Central <=11.5.2600.15 PrivEsc via Outdated Component Zohocorp ManageEngine Endpoint Central versions below 11.5.2600.15 are vulnerable to Privilege Escalation Due to Outdated Component
Manageengine Endpoint Central
CVE-2026-77699 Sep 07, 2026
Local Priv Escal in Zohocorp ManageEngine Endpoint Central <11.5.2605.01 DLL Load Zohocorp ManageEngine Endpoint Central versions below 11.5.2605.01 are vulnerable to Local privilege escalation due to loading a dll from an untrusted path.
Manageengine Endpoint Central
CVE-2026-77698 Sep 07, 2026
Local Privilege Escalation in Zoho Endpoint Central <= 11.5.2605.01 Zohocorp ManageEngine Endpoint Central versions before 11.5.2605.01 are vulnerable to local privilege escalation due to Agent upgrade.
Manageengine Endpoint Central
CVE-2026-14828 Sep 02, 2026
SQLi in Zohocorp ManageEngine Password Manager Pro <13235 Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerability.
Manageengine Password Manager Pro
Manageengine Pam360
Manageengine Access Manager Plus
And others...
CVE-2026-12263 Aug 13, 2026
Auth Bypass in ZOHOCorp Password Manager Pro via SAML Validation Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SAML validation.
Manageengine Password Manager Pro
Manageengine Pam360
CVE-2026-11840 Aug 13, 2026
Zohocorp ManageEngine Authenticated SQLi in Password Manager Pro & PAM360 Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions before 8552 are vulnerable to authenticated SQL injection.
Manageengine Password Manager Pro
Manageengine Pam360
CVE-2026-12571 Aug 11, 2026
Auth Bypass in ManageEngine DDI Central Pwd Reset Flow An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.
Manageengine Ddi Central
CVE-2026-16053 Aug 11, 2026
Authenticated Path Traversal in Zohocorp ManageEngine M365 Manager Plus Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Traversal vulnerability in Exchange Online backup module.
Manageengine M365 Manager Plus
Manageengine M365 Security Plus
CVE-2026-6516 Jul 23, 2026
Unauth RCE via Agent API in ManageEngine ADAudit Plus <8606 Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.
Manageengine Adaudit Plus
CVE-2026-3183 Jul 21, 2026
ManageEngine ADSelfService Plus MFA Bypass Vulnerability (CVE-2026-3183) Zohocorp ManageEngine ADSelfService Plus versions before 6524 are vulnerable to Multi Factor Authentication Bypass.
Manageengine Adselfservice Plus
CVE-2026-3182 Jul 21, 2026
Endpoint Central v<11.4.2528.34 Cleartext Sensitive Data Transmission Zohocorp ManageEngine Endpoint Central versions before 11.4.2528.34 are affected by cleartext transmission of sensitive information vulnerability.
Manageengine Endpoint Central
CVE-2026-11374 Jun 23, 2026
ManageEngine ADSelfService Plus SSO Ticket Prediction Enables Account Takeover In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by an unauthenticated user, leading to account takeover.
Manageengine Adselfservice Plus
Manageengine Recoverymanager Plus
Manageengine M365 Manager Plus
And others...
CVE-2026-8174 May 26, 2026
Zoho Mail WP Plugin <1.6.2: CSRF Vulnerability (CVE-2026-8174) Zohocorp Zoho Mail wordpress plugin is vulnerable to Cross-Site request forgery (CSRF). This issue affects Zoho Mail wordpress plugin versions before 1.6.2.
Zoho Mail Wordpress Plugin
CVE-2026-2740 May 21, 2026
Auth RCE in Zohocorp ManageEngine ADSelfService Plus via Dependency Zohocorp ManageEngine ADSelfService Plus version before 6525, DataSecurity Plus before 6264 and RecoveryManager Plus before 6313 are vulnerable to Authenticated Remote code execution in the agent machines due to the bug in the 3rd party dependency.
Manageengine Adselfservice Plus
Manageengine Datasecurity Plus
Manageengine Recoverymanager Plus
And others...
CVE-2026-3324 Apr 16, 2026
Auth Bypass in ManageEngine Log360 via Improper Filter Zohocorp ManageEngine Log360 versions 13000 through 13013 are vulnerable to authentication bypass on certain actions due to improper filter configuration.
Manageengine Log360
CVE-2026-5785 Apr 16, 2026
Authenticated SQLi in ManageEngine PAM360/Password Manager Pro Query Report Zohocorp ManageEngine PAM360 versions before 8531 and ManageEngine Password Manager Pro versions from 8600 to 13230 are vulnerable to Authenticated SQL injection in the query report module.
Manageengine Pam360
Manageengine Password Manager Pro
CVE-2026-27655 Apr 03, 2026
Stored XSS in Permissions Based on Mailboxes report in MEER Plus Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions Based on Mailboxes report.
Manageengine Exchange Reporter Plus
CVE-2026-4108 Apr 03, 2026
Stored XSS in Mailbox Permission Report Exchange Reporter Plus < 5802 Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Non-Owner Mailbox Permission report.
Manageengine Exchange Reporter Plus
CVE-2026-4107 Apr 03, 2026
Stored XSS in ManageEngine Exchange Reporter Plus Folder Report Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Folder Message Count and Size report.
Manageengine Exchange Reporter Plus
CVE-2026-3880 Apr 03, 2026
ManageEngine ERP Stored XSS via Public Folder Client Permissions Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Public Folder Client Permissions report.
Manageengine Exchange Reporter Plus
CVE-2026-3879 Apr 03, 2026
ManageEngine Exchange Reporter Plus Stored XSS in Equipment Mailbox Details Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Equipment Mailbox Details report.
Manageengine Exchange Reporter Plus
CVE-2026-28703 Apr 03, 2026
ManageEngine ER+ Stored XSS in Mails Exchanged Report (v<5802) Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Mails Exchanged Between Users report.
Manageengine Exchange Reporter Plus
CVE-2026-28756 Apr 03, 2026
StoreXSS in Zohocorp ManageEngine ER report for Distribution Groups Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions based on Distribution Groups report.
Manageengine Exchange Reporter Plus
CVE-2026-28754 Apr 03, 2026
Zohocorp ManageEngine ERP Stored XSS in Distribution Lists Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Distribution Lists report.
Manageengine Exchange Reporter Plus
CVE-2026-1367 Feb 23, 2026
ManageEngine ADSelfService Plus Authenticated SQLi via Search Report Zohocorp ManageEngine ADSelfService Plus versions 6522 and below are vulnerable to authenticated SQL Injection in the search report option.
Manageengine Adselfservice Plus
CVE-2025-9226 Jan 30, 2026
Stored XSS in Subnet Details of Zoho ManageEngine OpManager Zohocorp ManageEngine OpManager, NetFlow Analyzer, and OpUtils versions prior to 128582 are affected by a stored cross-site scripting vulnerability in the Subnet Details.
Manageengine Opmanager
Manageengine Netflow Analyzer
Manageengine Oputils
And others...
CVE-2025-11669 Jan 13, 2026
Zohocorp ManageEngine PAM360 Auth Issue in Remote Session Initiation Zohocorp ManageEngine PAM360 versions before 8202; Password Manager Pro versions before 13221; Access Manager Plus versions prior to 4401 are vulnerable to an authorization issue in the initiate remote session functionality.
Manageengine Pam360
Manageengine Password Manager Pro
Manageengine Access Manager Plus
And others...
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.