OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-86677

HIGH · CVSS 8.8 EPSS 2.02% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

ZohoCorp ManageEngine Applications Manager versions 182000 and below are vulnerable to unauthorized SQL command execution by low-privileged users, which could lead to escalated privileges and remote code execution. Organizations using these versions should prioritize patching to mitigate the risk of potential data breaches and system compromise. Immediate action is recommended for those managing sensitive data or critical infrastructure.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-86677
Severity
HIGH
CVSS
8.8
EPSS
2.02%

Original NVD Description

ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to run unauthorized SQL commands, potentially gaining administrator access and remote code execution.