Search
Search Results (5 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-12264 | 1 Zohocorp | 1 Ddi Central | 2026-09-28 | 8.8 High |
| Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Arbitrary file write via HA Failover Config sync upload leading to remote code execution. | ||||
| CVE-2026-12269 | 1 Zohocorp | 1 Ddi Central | 2026-09-28 | 8.8 High |
| Zohocorp ManageEngine DDI Central 6.2.0 build below 6201 had a Keepalived configuration injection vulnerability in the HA configuration workflow. This issue could allow an authenticated operator-level user to modify the Keepalived configuration and potentially execute commands as root on the DDI Central host. | ||||
| CVE-2026-12268 | 1 Zohocorp | 1 Ddi Central | 2026-09-28 | 8.8 High |
| ManageEngine DDI Central versions below 6201 are vulnerable to PowerShell command injection in Windows DNS SPF/TXT record push leading to remote code execution. | ||||
| CVE-2026-12267 | 1 Zohocorp | 1 Ddi Central | 2026-09-28 | 7.2 High |
| ManageEngine DDI Central versions below 6201 are vulnerable to Command injection in Windows DNS Query Resolution Policy name field leading to remote code execution. | ||||
| CVE-2026-12265 | 1 Zohocorp | 1 Ddi Central | 2026-09-28 | 8.8 High |
| Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Insufficient access control in HA failover endpoint leading to destructive PostgreSQL database operations. | ||||
Page 1 of 1.