← Back to search

CVE-2026-19599

9.9 CRITICAL

Published 2026-09-23 · Updated 2026-09-24

AI risk analysis

Summary
This vulnerability allows remote code execution in the Notification Profile module of ZohoCorp ManageEngine OpManager MSP versions 12.8.709 and below, enabling attackers to execute arbitrary code on the affected system.
Exploitability
Exploitation is relatively straightforward given the remote code execution capability, requiring only access to the Notification Profile module.
Blast radius
If exploited, this vulnerability could lead to complete control of the affected system, potentially leading to data theft, system compromise, and further attacks.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to ZohoCorp ManageEngine OpManager MSP version 12.8.710 or later.
rceremote-code-executionnotification-profilecritical

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

ZohoCorp ManageEngine OpManager MSP versions 12.8.709 and below were vulnerable to a Remote Code Execution vulnerability in the Notification Profile module.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-78

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.