Skip to content

ManageEngine Critical Vulnerabilities - 20260924001

Overview

The WASOC has observed updates from Zohocorp relating to multiple critical vulnerabilities affecting their ManageEngine products. In some products, successful exploitation could allow an unauthenticated attacker to impersonate the service account and access or modify associated cloud resources.

What is vulnerable?

Product(s) Affected Version(s) CVE CVSS Severity
ManageEngine Applications Manager Versions 182200 and below CVE-2026-86708 10 Critical
ManageEngine ADSelfService Plus Versions 7000 and below CVE-2026-74849 9.8 Critical
ManageEngine OpManager MSP Versions 12.8.709 and below CVE-2026-19599 9.9 Critical

What has been observed?

The WASOC has not received any reports of exploitation of this vulnerability on Western Australian Government networks at the time of writing.

Recommendation

The WASOC recommends administrators apply the solutions as per vendor instructions to all affected devices within expected timeframes (refer Patch Management):