CVE-2026-12370
published 2026-09-23CVE-2026-12370: ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.667 and below were vulnerable to a Server-Side Template…
PriorityP260high7.6CVSS 3.1
AVNACLPRLUINSUCHILAL
EPSS
1.52%
73.5th percentile
ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.667 and below were vulnerable to a Server-Side Template Injection vulnerability in Configlet processing, which could lead to Remote Code Execution.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| zohocorp | manageengine_netflow_analyzer | < 12.8.668 | 12.8.668 |
| zohocorp | manageengine_network_configuration_manager | < 12.8.668 | 12.8.668 |
| zohocorp | manageengine_opmanager | < 12.8.668 | 12.8.668 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-23
Published