CVE-2026-12370 vulnerability in Zoho Corp Products
Published on September 23, 2026
Remote Code Execution Vulnerability
ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.667 and below were vulnerable to a Server-Side Template Injection vulnerability in Configlet processing, which could lead to Remote Code Execution.
Vulnerability Analysis
CVE-2026-12370 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.
Weakness Type
Products Associated with CVE-2026-12370
Want to know whenever a new CVE is published for Zoho Corp products? stack.watch will email you.
Affected Versions
Zohocorp ManageEngine OpManager:- Before 12.8.668 is affected.
- Before 12.8.668 is affected.
- Before 12.8.668 is affected.