OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-76978

HIGH · CVSS 8.8 EPSS 3.72%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and earlier are susceptible to a command injection vulnerability in the Diagnose Settings feature, allowing attackers to execute arbitrary commands on the server. This high-severity flaw (CVSS 8.8) poses significant risks, including unauthorized access and potential system compromise. Organizations using these affected products should prioritize immediate patching to mitigate potential exploitation.

CVE
CVE-2026-76978
Severity
HIGH
CVSS
8.8
EPSS
3.72%

Original NVD Description

ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to a Command Injection vulnerability in the Diagnose Settings feature.