OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-12268

HIGH · CVSS 8.8 EPSS 4.73% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-28 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

ManageEngine DDI Central versions prior to 6201 are susceptible to a PowerShell command injection vulnerability in the Windows DNS SPF/TXT record push feature, which could allow an attacker to execute arbitrary code remotely. Organizations using affected versions should prioritize patching to mitigate the risk of exploitation, as the high severity rating indicates significant potential impact on system integrity and security.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-12268
Severity
HIGH
CVSS
8.8
EPSS
4.73%
Windows

Original NVD Description

ManageEngine DDI Central versions below 6201 are vulnerable to PowerShell command injection in Windows DNS SPF/TXT record push leading to remote code execution.