Zoho Corp Ddi Central
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Zoho Corp Ddi Central.
By the Year
In 2026 there have been 5 vulnerabilities in Zoho Corp Ddi Central with an average score of 8.5 out of ten.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 5 | 8.48 |
It may take a day or so for new Ddi Central vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Zoho Corp Ddi Central Security Vulnerabilities
Zohocorp DDI Central: HA Failover Endpoint ACL Flaw Enables Destructive DB Ops
CVE-2026-12265
8.8 - High
- September 28, 2026
Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Insufficient access control in HA failover endpoint leading to destructive PostgreSQL database operations.
Authorization
Arbitrary File Write in ManageEngine DDI Central (pre-6201) RCE
CVE-2026-12264
8.8 - High
- September 28, 2026
Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Arbitrary file write via HA Failover Config sync upload leading to remote code execution.
Unrestricted File Upload
ManageEngine DDI Central RCE via Windows DNS Query Injection
CVE-2026-12267
7.2 - High
- September 28, 2026
ManageEngine DDI Central versions below 6201 are vulnerable to Command injection in Windows DNS Query Resolution Policy name field leading to remote code execution.
Improper Input Validation
PowerShell Command Injection in ManageEngine DDI Central DNS SPF/TXT Push
CVE-2026-12268
8.8 - High
- September 28, 2026
ManageEngine DDI Central versions below 6201 are vulnerable to PowerShell command injection in Windows DNS SPF/TXT record push leading to remote code execution.
Improper Input Validation
Keepalived Config Injection in Zoho DDI Central <6.2.0 build 6201
CVE-2026-12269
8.8 - High
- September 28, 2026
Zohocorp ManageEngine DDI Central 6.2.0 build below 6201 had a Keepalived configuration injection vulnerability in the HA configuration workflow. This issue could allow an authenticated operator-level user to modify the Keepalived configuration and potentially execute commands as root on the DDI Central host.
Unrestricted File Upload
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Zoho Corp Ddi Central or by Zoho Corp? Click the Watch button to subscribe.