ManageEngine Critical Vulnerabilities - 20260924001¶
Overview¶
The WASOC has observed updates from Zohocorp relating to multiple critical vulnerabilities affecting their ManageEngine products. In some products, successful exploitation could allow an unauthenticated attacker to impersonate the service account and access or modify associated cloud resources.
What is vulnerable?¶
| Product(s) Affected | Version(s) | CVE | CVSS | Severity |
|---|---|---|---|---|
| ManageEngine Applications Manager | Versions 182200 and below | CVE-2026-86708 | 10 | Critical |
| ManageEngine ADSelfService Plus | Versions 7000 and below | CVE-2026-74849 | 9.8 | Critical |
| ManageEngine OpManager MSP | Versions 12.8.709 and below | CVE-2026-19599 | 9.9 | Critical |
What has been observed?¶
The WASOC has not received any reports of exploitation of this vulnerability on Western Australian Government networks at the time of writing.
Recommendation¶
The WASOC recommends administrators apply the solutions as per vendor instructions to all affected devices within expected timeframes (refer Patch Management):