cbcvebase.
CVE-2026-12370
published 2026-09-23

CVE-2026-12370: ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.667 and below were vulnerable to a Server-Side Template…

PriorityP260high7.6CVSS 3.1
AVNACLPRLUINSUCHILAL
EPSS
1.52%
73.5th percentile
ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.667 and below were vulnerable to a Server-Side Template Injection vulnerability in Configlet processing, which could lead to Remote Code Execution.

Affected

3 ranges
VendorProductVersion rangeFixed in
zohocorpmanageengine_netflow_analyzer< 12.8.66812.8.668
zohocorpmanageengine_network_configuration_manager< 12.8.66812.8.668
zohocorpmanageengine_opmanager< 12.8.66812.8.668
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.