CVE-2026-19599
9.9 CRITICALPublished 2026-09-23 · Updated 2026-09-24
AI risk analysis
- Summary
- This vulnerability allows remote code execution in the Notification Profile module of ZohoCorp ManageEngine OpManager MSP versions 12.8.709 and below, enabling attackers to execute arbitrary code on the affected system.
- Exploitability
- Exploitation is relatively straightforward given the remote code execution capability, requiring only access to the Notification Profile module.
- Blast radius
- If exploited, this vulnerability could lead to complete control of the affected system, potentially leading to data theft, system compromise, and further attacks.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to ZohoCorp ManageEngine OpManager MSP version 12.8.710 or later.
rceremote-code-executionnotification-profilecritical
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
ZohoCorp ManageEngine OpManager MSP versions 12.8.709 and below were vulnerable to a Remote Code Execution vulnerability in the Notification Profile module.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Weaknesses
CWE-78
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2026-70416
- CRITICALCVE-2026-91843
- HIGHCVE-2026-18900PoC
- CRITICALCVE-2026-74849
- CRITICALCVE-2026-80145
- CRITICALCVE-2026-80151
- MEDIUMCVE-2026-94490
- CRITICALCVE-2026-95675
Related by shared AI tags and CWE weakness class. Browse the full archive.