Zoho Corp ZoHo
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Zoho Corp product.
RSS Feeds for Zoho Corp security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Zoho Corp products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Zoho Corp Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 52 vulnerabilities in Zoho Corp with an average score of 7.7 out of ten. Last year, in 2025 Zoho Corp had 31 security vulnerabilities published. That is, 21 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 1.31.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 52 | 7.71 |
| 2025 | 31 | 6.40 |
| 2024 | 53 | 8.10 |
| 2023 | 46 | 6.91 |
| 2022 | 55 | 7.67 |
| 2021 | 96 | 8.63 |
| 2020 | 40 | 7.72 |
| 2019 | 58 | 7.53 |
| 2018 | 48 | 7.76 |
It may take a day or so for new Zoho Corp vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Zoho Corp Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-92905 | Sep 24, 2026 |
Zoho ManageEngine EventLog Analyzer DoS via malformed syslog packetsZohoCorp ManageEngine EventLog Analyzer and Log360 before build 13071 were vulnerable to a DoS vulnerability that allowed attackers to crash the log collector using malformed syslog packets. |
|
| CVE-2026-86678 | Sep 23, 2026 |
ZohoCorp ManageEngine Applications Manager versions 182000 and belowZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to obtain an administrators API key and use it to perform administrator-level actions. |
|
| CVE-2026-86677 | Sep 23, 2026 |
ZohoCorp ManageEngine Applications Manager versions 182000 and belowZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to run unauthorized SQL commands, potentially gaining administrator access and remote code execution. |
|
| CVE-2026-86679 | Sep 23, 2026 |
ZohoCorp ManageEngine Applications Manager versions 182000 and below were vulnerable to a permissions validation issueZohoCorp ManageEngine Applications Manager versions 182000 and below were vulnerable to a permissions validation issue that allowed a low-privileged user to delete service monitors outside their assigned scope. |
|
| CVE-2026-86683 | Sep 23, 2026 |
ZohoCorp ManageEngine Applications Manager versions 182000 and belowZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to change the proxy settings. |
|
| CVE-2026-86681 | Sep 23, 2026 |
ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to a permissions validation issueZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to a permissions validation issue that allowed low-privileged users to execute administrator-configured MBean actions on monitors outside their assigned scope. |
|
| CVE-2026-86708 | Sep 23, 2026 |
ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private key in the Applications Manager installer, which couldZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private key in the Applications Manager installer, which could allow an unauthenticated attacker to impersonate the service account and access or modify associated cloud resources. |
|
| CVE-2026-19599 | Sep 23, 2026 |
RCE in Zoho ManageEngine OpManager MSP <=12.8.709 Notification ProfileZohoCorp ManageEngine OpManager MSP versions 12.8.709 and below were vulnerable to a Remote Code Execution vulnerability in the Notification Profile module. |
|
| CVE-2026-75825 | Sep 23, 2026 |
Auth Bypass in ZohoCorp ManageEngine OpManager <12.8.710 with AppMgr PluginZohoCorp ManageEngine OpManager versions 12.8.710 and below with the Application Manager Plugin enabled were vulnerable to an Authentication Bypass vulnerability. |
|
| CVE-2026-76978 | Sep 23, 2026 |
Zoho ManageEngine OpManager <12.8.709: Cmd Injection via Diagnose SettingsZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to a Command Injection vulnerability in the Diagnose Settings feature. |
|
| CVE-2026-76979 | Sep 23, 2026 |
XML Injection in ZohoCorp OpManager <=12.8.709ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to an XML Injection vulnerability in the Rule Tracking Compare Policies feature. |
|
| CVE-2026-76980 | Sep 23, 2026 |
Data Exposure in ManageEngine Firewall Analyzer Syslog Collector 12.8.709ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to a Data Exposure vulnerability in the Firewall Analyzer syslog collector. |
|
| CVE-2026-84787 | Sep 23, 2026 |
ZohoCorp OpMgr & FW Analyzer <12.8.710 Priv Esc via Report Profile ImportZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Privilege Escalation vulnerability that allowed an authenticated low-privilege user to gain Administrator privileges through Report Profile import. |
|
| CVE-2026-84789 | Sep 23, 2026 |
OpManager/Firewall Analyzer <=12.8.710: Broken Control - Unauthorized AlertsZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to create alert notifications for firewalls outside their assigned scope. |
|
| CVE-2026-84791 | Sep 23, 2026 |
OpMgr <12.8.710: Broken AC Change Report SchedulesZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to modify Change Management report schedule configurations for firewalls outside their assigned scope. |
|
| CVE-2026-15358 | Sep 23, 2026 |
OpManager & Net Config Manager <12.8.671 Path Traversal VulnerabilityZohoCorp ManageEngine OpManager and Network Configuration Manager versions before 12.8.671 were vulnerable to an unauthorized Path Traversal vulnerability. |
|
| CVE-2026-14913 | Sep 23, 2026 |
ZohoCorp ManageEngine OpManager <=12.8.669 SQLi in Rule Mgmt Search ReportsZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.669 and below were vulnerable to an SQL Injection vulnerability in Rule Management Search Reports. |
|
| CVE-2026-12370 | Sep 23, 2026 |
ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.667 and below were vulnerable to a Server-Side Template Injection vulnerability in Configlet processingZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.667 and below were vulnerable to a Server-Side Template Injection vulnerability in Configlet processing, which could lead to Remote Code Execution. |
And others... |
| CVE-2026-75791 | Sep 22, 2026 |
Zohocorp ADSelfService Plus REST API Auth BypassZohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to an authentication bypass vulnerability in the REST API. |
|
| CVE-2026-74849 | Sep 22, 2026 |
Remote Code Execution via GINA Client in ManageEngine ADSelfService PlusZohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to a remote code execution vulnerability in the GINA client. |
|
| CVE-2026-18912 | Sep 18, 2026 |
Auth SQLi in ManageEngine DataSecurity Plus Reports ModuleManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allowing an authenticated technician to execute arbitrary SQL queries through the Reports module. |
|
| CVE-2026-18911 | Sep 18, 2026 |
DataSecurity Plus Agent Auth Bypass Pre6310ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolled agents to send requests without proper authentication. |
|
| CVE-2026-77697 | Sep 07, 2026 |
PrivEsc Vulnerability in Zohocorp Endpoint Central <11.4.2540.23 via JARZohocorp ManageEngine Endpoint Central versions below 11.4.2540.23 are vulnerable to Privilege Escalation During JAR Extraction |
|
| CVE-2026-85640 | Sep 07, 2026 |
ManageEngine Endpoint Central <=11.5.2600.15 PrivEsc via Outdated ComponentZohocorp ManageEngine Endpoint Central versions below 11.5.2600.15 are vulnerable to Privilege Escalation Due to Outdated Component |
|
| CVE-2026-77699 | Sep 07, 2026 |
Local Priv Escal in Zohocorp ManageEngine Endpoint Central <11.5.2605.01 DLL LoadZohocorp ManageEngine Endpoint Central versions below 11.5.2605.01 are vulnerable to Local privilege escalation due to loading a dll from an untrusted path. |
|
| CVE-2026-77698 | Sep 07, 2026 |
Local Privilege Escalation in Zoho Endpoint Central <= 11.5.2605.01Zohocorp ManageEngine Endpoint Central versions before 11.5.2605.01 are vulnerable to local privilege escalation due to Agent upgrade. |
|
| CVE-2026-14828 | Sep 02, 2026 |
SQLi in Zohocorp ManageEngine Password Manager Pro <13235Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerability. |
And others... |
| CVE-2026-12263 | Aug 13, 2026 |
Auth Bypass in ZOHOCorp Password Manager Pro via SAML ValidationZohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SAML validation. |
|
| CVE-2026-11840 | Aug 13, 2026 |
Zohocorp ManageEngine Authenticated SQLi in Password Manager Pro & PAM360Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions before 8552 are vulnerable to authenticated SQL injection. |
|
| CVE-2026-12571 | Aug 11, 2026 |
Auth Bypass in ManageEngine DDI Central Pwd Reset FlowAn authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover. |
|
| CVE-2026-16053 | Aug 11, 2026 |
Authenticated Path Traversal in Zohocorp ManageEngine M365 Manager PlusZohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Traversal vulnerability in Exchange Online backup module. |
|
| CVE-2026-6516 | Jul 23, 2026 |
Unauth RCE via Agent API in ManageEngine ADAudit Plus <8606Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API. |
|
| CVE-2026-3183 | Jul 21, 2026 |
ManageEngine ADSelfService Plus MFA Bypass Vulnerability (CVE-2026-3183)Zohocorp ManageEngine ADSelfService Plus versions before 6524 are vulnerable to Multi Factor Authentication Bypass. |
|
| CVE-2026-3182 | Jul 21, 2026 |
Endpoint Central v<11.4.2528.34 Cleartext Sensitive Data TransmissionZohocorp ManageEngine Endpoint Central versions before 11.4.2528.34 are affected by cleartext transmission of sensitive information vulnerability. |
|
| CVE-2026-11374 | Jun 23, 2026 |
ManageEngine ADSelfService Plus SSO Ticket Prediction Enables Account TakeoverIn ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by an unauthenticated user, leading to account takeover. |
And others... |
| CVE-2026-8174 | May 26, 2026 |
Zoho Mail WP Plugin <1.6.2: CSRF Vulnerability (CVE-2026-8174)Zohocorp Zoho Mail wordpress plugin is vulnerable to Cross-Site request forgery (CSRF). This issue affects Zoho Mail wordpress plugin versions before 1.6.2. |
|
| CVE-2026-2740 | May 21, 2026 |
Auth RCE in Zohocorp ManageEngine ADSelfService Plus via DependencyZohocorp ManageEngine ADSelfService Plus version before 6525, DataSecurity Plus before 6264 and RecoveryManager Plus before 6313 are vulnerable to Authenticated Remote code execution in the agent machines due to the bug in the 3rd party dependency. |
And others... |
| CVE-2026-3324 | Apr 16, 2026 |
Auth Bypass in ManageEngine Log360 via Improper FilterZohocorp ManageEngine Log360 versions 13000 through 13013 are vulnerable to authentication bypass on certain actions due to improper filter configuration. |
|
| CVE-2026-5785 | Apr 16, 2026 |
Authenticated SQLi in ManageEngine PAM360/Password Manager Pro Query ReportZohocorp ManageEngine PAM360 versions before 8531 and ManageEngine Password Manager Pro versions from 8600 to 13230 are vulnerable to Authenticated SQL injection in the query report module. |
|
| CVE-2026-27655 | Apr 03, 2026 |
Stored XSS in Permissions Based on Mailboxes report in MEER PlusZohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions Based on Mailboxes report. |
|
| CVE-2026-4108 | Apr 03, 2026 |
Stored XSS in Mailbox Permission Report Exchange Reporter Plus < 5802Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Non-Owner Mailbox Permission report. |
|
| CVE-2026-4107 | Apr 03, 2026 |
Stored XSS in ManageEngine Exchange Reporter Plus Folder ReportZohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Folder Message Count and Size report. |
|
| CVE-2026-3880 | Apr 03, 2026 |
ManageEngine ERP Stored XSS via Public Folder Client PermissionsZohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Public Folder Client Permissions report. |
|
| CVE-2026-3879 | Apr 03, 2026 |
ManageEngine Exchange Reporter Plus Stored XSS in Equipment Mailbox DetailsZohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Equipment Mailbox Details report. |
|
| CVE-2026-28703 | Apr 03, 2026 |
ManageEngine ER+ Stored XSS in Mails Exchanged Report (v<5802)Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Mails Exchanged Between Users report. |
|
| CVE-2026-28756 | Apr 03, 2026 |
StoreXSS in Zohocorp ManageEngine ER report for Distribution GroupsZohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions based on Distribution Groups report. |
|
| CVE-2026-28754 | Apr 03, 2026 |
Zohocorp ManageEngine ERP Stored XSS in Distribution ListsZohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Distribution Lists report. |
|
| CVE-2026-1367 | Feb 23, 2026 |
ManageEngine ADSelfService Plus Authenticated SQLi via Search ReportZohocorp ManageEngine ADSelfService Plus versions 6522 and below are vulnerable to authenticated SQL Injection in the search report option. |
|
| CVE-2025-9226 | Jan 30, 2026 |
Stored XSS in Subnet Details of Zoho ManageEngine OpManagerZohocorp ManageEngine OpManager, NetFlow Analyzer, and OpUtils versions prior to 128582 are affected by a stored cross-site scripting vulnerability in the Subnet Details. |
And others... |
| CVE-2025-11669 | Jan 13, 2026 |
Zohocorp ManageEngine PAM360 Auth Issue in Remote Session InitiationZohocorp ManageEngine PAM360 versions before 8202; Password Manager Pro versions before 13221; Access Manager Plus versions prior to 4401 are vulnerable to an authorization issue in the initiate remote session functionality. |
And others... |