{"schema_version":1,"title":"Zoho vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 29 vulnerabilities in Zoho: 15 in the last 7 days and 18 in the last 90 days, 11 of them critical and 9 exploited in the wild. The most recent, CVE-2026-86683, was published on 23 September 2026. 1 technology has a page of its own.","url":"https://junglewise.ai/threats/vendors/zoho","json_url":"https://junglewise.ai/threats/vendors/zoho.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/zoho","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":15,"all_time":29,"critical":11,"exploited":9,"last_7_days":15,"last_30_days":17,"last_90_days":18,"last_365_days":20},"latest":[{"cve":"CVE-2026-86683","cvss":8.1,"epss":0.0068,"slug":"cve-2026-86683-zohocorp-manageengine-applications-manager-versions-182000-and","title":"Zoho ManageEngine Applications Manager privilege escalation in proxy settings","severity":"high","exploited":false,"published_at":"2026-09-23T14:17:09.347+00:00","url":"https://junglewise.ai/threats/cve-2026-86683-zohocorp-manageengine-applications-manager-versions-182000-and"},{"cve":"CVE-2026-86679","cvss":7.1,"epss":0.0078,"slug":"cve-2026-86679-zohocorp-manageengine-applications-manager-versions-182000-and","title":"Zoho ManageEngine Applications Manager permission bypass in service monitor deletion","severity":"high","exploited":false,"published_at":"2026-09-23T14:17:09.09+00:00","url":"https://junglewise.ai/threats/cve-2026-86679-zohocorp-manageengine-applications-manager-versions-182000-and"},{"cve":"CVE-2026-86678","cvss":8.8,"epss":0.0068,"slug":"cve-2026-86678-zohocorp-manageengine-applications-manager-versions-182000-and","title":"Zoho ManageEngine Applications Manager API key disclosure","severity":"high","exploited":false,"published_at":"2026-09-23T14:17:08.963+00:00","url":"https://junglewise.ai/threats/cve-2026-86678-zohocorp-manageengine-applications-manager-versions-182000-and"},{"cve":"CVE-2026-86677","cvss":8.8,"epss":0.0202,"slug":"cve-2026-86677-zohocorp-manageengine-applications-manager-versions-182000-and","title":"Zoho ManageEngine Applications Manager privilege escalation in synchronization","severity":"high","exploited":false,"published_at":"2026-09-23T14:17:08.803+00:00","url":"https://junglewise.ai/threats/cve-2026-86677-zohocorp-manageengine-applications-manager-versions-182000-and"},{"cve":"CVE-2026-76980","cvss":7.4,"epss":0.0039,"slug":"cve-2026-76980-zohocorp-manageengine-opmanager-and-firewall-analyzer-versions-12","title":"Zoho ManageEngine OpManager and Firewall Analyzer credential exposure in syslog collector","severity":"high","exploited":false,"published_at":"2026-09-23T13:17:29.393+00:00","url":"https://junglewise.ai/threats/cve-2026-76980-zohocorp-manageengine-opmanager-and-firewall-analyzer-versions-12"},{"cve":"CVE-2026-76979","cvss":7.7,"epss":0.0113,"slug":"cve-2026-76979-zohocorp-manageengine-opmanager-and-firewall-analyzer-versions-12","title":"Zoho ManageEngine OpManager and Firewall Analyzer XML injection in Rule Tracking","severity":"high","exploited":false,"published_at":"2026-09-23T13:17:29.273+00:00","url":"https://junglewise.ai/threats/cve-2026-76979-zohocorp-manageengine-opmanager-and-firewall-analyzer-versions-12"},{"cve":"CVE-2026-76978","cvss":8.8,"epss":0.0373,"slug":"cve-2026-76978-zohocorp-manageengine-opmanager-and-firewall-analyzer-versions-12","title":"Zoho ManageEngine OpManager and Firewall Analyzer command injection in Diagnose Settings","severity":"high","exploited":false,"published_at":"2026-09-23T13:17:29.153+00:00","url":"https://junglewise.ai/threats/cve-2026-76978-zohocorp-manageengine-opmanager-and-firewall-analyzer-versions-12"},{"cve":"CVE-2026-19599","cvss":9.9,"epss":0.0286,"slug":"cve-2026-19599-zohocorp-manageengine-opmanager-msp-versions-12-8-709-and-below","title":"Zoho ManageEngine OpManager MSP remote code execution in Notification Profile","severity":"critical","exploited":false,"published_at":"2026-09-23T13:17:27.4+00:00","url":"https://junglewise.ai/threats/cve-2026-19599-zohocorp-manageengine-opmanager-msp-versions-12-8-709-and-below"},{"cve":"CVE-2026-84791","cvss":7.1,"epss":0.006,"slug":"cve-2026-84791-zohocorp-manageengine-opmanager-and-firewall-analyzer-versions-12","title":"Zoho ManageEngine OpManager and Firewall Analyzer access control bypass","severity":"high","exploited":false,"published_at":"2026-09-23T12:17:08.11+00:00","url":"https://junglewise.ai/threats/cve-2026-84791-zohocorp-manageengine-opmanager-and-firewall-analyzer-versions-12"},{"cve":"CVE-2026-84787","cvss":8.1,"epss":0.0085,"slug":"cve-2026-84787-zohocorp-manageengine-opmanager-and-firewall-analyzer-versions-12","title":"Zoho ManageEngine OpManager privilege escalation through Report Profile import","severity":"high","exploited":false,"published_at":"2026-09-23T12:17:07.857+00:00","url":"https://junglewise.ai/threats/cve-2026-84787-zohocorp-manageengine-opmanager-and-firewall-analyzer-versions-12"},{"cve":"CVE-2026-15358","cvss":7.5,"epss":0.0109,"slug":"cve-2026-15358-zohocorp-manageengine-opmanager-and-network-configuration-manager","title":"ManageEngine OpManager path traversal in Smart Update Manager","severity":"high","exploited":false,"published_at":"2026-09-23T12:17:05.63+00:00","url":"https://junglewise.ai/threats/cve-2026-15358-zohocorp-manageengine-opmanager-and-network-configuration-manager"},{"cve":"CVE-2026-14913","cvss":8.8,"epss":0.0097,"slug":"cve-2026-14913-zohocorp-manageengine-opmanager-and-firewall-analyzer-versions-12","title":"Zoho ManageEngine OpManager SQL injection in Rule Management Search Reports","severity":"high","exploited":false,"published_at":"2026-09-23T12:17:05.507+00:00","url":"https://junglewise.ai/threats/cve-2026-14913-zohocorp-manageengine-opmanager-and-firewall-analyzer-versions-12"},{"cve":"CVE-2026-12370","cvss":7.6,"epss":0.0152,"slug":"cve-2026-12370-zohocorp-manageengine-opmanager-netflow-analyzer-and-network","title":"Zoho ManageEngine OpManager SSTI in Configlet processing","severity":"high","exploited":false,"published_at":"2026-09-23T12:17:05.373+00:00","url":"https://junglewise.ai/threats/cve-2026-12370-zohocorp-manageengine-opmanager-netflow-analyzer-and-network"},{"cve":"CVE-2026-75791","cvss":8.6,"epss":0.0172,"slug":"cve-2026-75791-zohocorp-manageengine-adselfservice-plus-versions-before-build","title":"Zoho ManageEngine ADSelfService Plus authentication bypass in REST API","severity":"high","exploited":false,"published_at":"2026-09-22T13:17:11.17+00:00","url":"https://junglewise.ai/threats/cve-2026-75791-zohocorp-manageengine-adselfservice-plus-versions-before-build"},{"cve":"CVE-2026-74849","cvss":9.8,"epss":0.0461,"slug":"cve-2026-74849-zohocorp-manageengine-adselfservice-plus-versions-before-build","title":"Zoho ManageEngine ADSelfService Plus remote code execution in GINA client","severity":"critical","exploited":false,"published_at":"2026-09-22T12:17:14.007+00:00","url":"https://junglewise.ai/threats/cve-2026-74849-zohocorp-manageengine-adselfservice-plus-versions-before-build"},{"cve":"CVE-2026-77699","cvss":5,"epss":0.0029,"slug":"cve-2026-77699-zoho-manageengine-endpoint-central-privilege-escalation-via-dll","title":"Zoho ManageEngine Endpoint Central privilege escalation via DLL loading","severity":"medium","exploited":false,"published_at":"2026-09-07T11:17:36.56+00:00","url":"https://junglewise.ai/threats/cve-2026-77699-zoho-manageengine-endpoint-central-privilege-escalation-via-dll"},{"cve":"CVE-2026-77698","cvss":5.7,"epss":0.0035,"slug":"cve-2026-77698-zoho-manageengine-endpoint-central-privilege-escalation-in-agent","title":"Zoho ManageEngine Endpoint Central privilege escalation in Agent upgrade","severity":"medium","exploited":false,"published_at":"2026-09-07T10:16:53.673+00:00","url":"https://junglewise.ai/threats/cve-2026-77698-zoho-manageengine-endpoint-central-privilege-escalation-in-agent"},{"cve":"CVE-2026-16053","cvss":8.5,"epss":0.0177,"slug":"cve-2026-16053-zoho-manageengine-m365-manager-plus-path-traversal-in-exchange","title":"Zoho ManageEngine M365 Manager Plus path traversal in Exchange Online backup","severity":"high","exploited":false,"published_at":"2026-08-11T07:17:28.233+00:00","url":"https://junglewise.ai/threats/cve-2026-16053-zoho-manageengine-m365-manager-plus-path-traversal-in-exchange"},{"cve":"CVE-2026-2740","cvss":8.4,"slug":"cve-2026-2740-manageengine-multiple-products-authenticated-rce-in-agent-machines","title":"ManageEngine multiple products authenticated RCE in agent machines","severity":"high","exploited":false,"published_at":"2026-05-21T14:16:44.85+00:00","url":"https://junglewise.ai/threats/cve-2026-2740-manageengine-multiple-products-authenticated-rce-in-agent-machines"},{"cve":"CVE-2025-67972","cvss":4.3,"epss":0.0005,"slug":"cve-2025-67972-zoho-zeptomail-missing-authorization-in-wordpress-plugin","title":"Zoho ZeptoMail missing authorization in WordPress plugin","severity":"medium","exploited":false,"published_at":"2026-02-20T16:22:03.43+00:00","url":"https://junglewise.ai/threats/cve-2025-67972-zoho-zeptomail-missing-authorization-in-wordpress-plugin"},{"cve":"CVE-2022-28810","cvss":6.8,"slug":"cve-2022-28810-zoho-manageengine-adselfservice-plus-remote-code-execution","title":"Zoho ManageEngine ADSelfService Plus Remote Code Execution Vulnerability","severity":"critical","exploited":true,"published_at":"2023-03-07T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2022-28810-zoho-manageengine-adselfservice-plus-remote-code-execution"},{"cve":"CVE-2022-47966","cvss":9.8,"slug":"cve-2022-47966-zoho-manageengine-multiple-products-remote-code-execution","title":"Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability","severity":"critical","exploited":true,"published_at":"2023-01-23T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2022-47966-zoho-manageengine-multiple-products-remote-code-execution"},{"cve":"CVE-2022-35405","cvss":9.8,"slug":"cve-2022-35405-zoho-manageengine-multiple-products-remote-code-execution","title":"Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability","severity":"critical","exploited":true,"published_at":"2022-09-22T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2022-35405-zoho-manageengine-multiple-products-remote-code-execution"},{"cve":"CVE-2021-44515","cvss":9.8,"slug":"cve-2021-44515-zoho-desktop-central-authentication-bypass-vulnerability","title":"Zoho Desktop Central Authentication Bypass Vulnerability","severity":"critical","exploited":true,"published_at":"2021-12-10T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2021-44515-zoho-desktop-central-authentication-bypass-vulnerability"},{"cve":"CVE-2021-37415","cvss":9.8,"slug":"cve-2021-37415-zoho-manageengine-servicedesk-authentication-bypass-vulnerability","title":"Zoho ManageEngine ServiceDesk Authentication Bypass Vulnerability","severity":"critical","exploited":true,"published_at":"2021-12-01T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2021-37415-zoho-manageengine-servicedesk-authentication-bypass-vulnerability"}],"vendor":{"hub":true,"name":"Zoho","slug":"zoho","homepage":"https://www.zoho.com/","description":"An Indian multinational technology company that focuses on web-based business tools and information technology management software.","url":"https://junglewise.ai/threats/vendors/zoho"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":2,"exploited":0,"vulnerabilities":15}],"most_severe":[{"cve":"CVE-2022-47966","cvss":9.8,"slug":"cve-2022-47966-zoho-manageengine-multiple-products-remote-code-execution","title":"Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability","severity":"critical","exploited":true,"published_at":"2023-01-23T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2022-47966-zoho-manageengine-multiple-products-remote-code-execution"},{"cve":"CVE-2022-35405","cvss":9.8,"slug":"cve-2022-35405-zoho-manageengine-multiple-products-remote-code-execution","title":"Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability","severity":"critical","exploited":true,"published_at":"2022-09-22T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2022-35405-zoho-manageengine-multiple-products-remote-code-execution"},{"cve":"CVE-2021-44515","cvss":9.8,"slug":"cve-2021-44515-zoho-desktop-central-authentication-bypass-vulnerability","title":"Zoho Desktop Central Authentication Bypass Vulnerability","severity":"critical","exploited":true,"published_at":"2021-12-10T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2021-44515-zoho-desktop-central-authentication-bypass-vulnerability"},{"cve":"CVE-2021-44077","cvss":9.8,"slug":"cve-2021-44077-zoho-manageengine-servicedesk-plus-remote-code-execution","title":"Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability","severity":"critical","exploited":true,"published_at":"2021-12-01T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2021-44077-zoho-manageengine-servicedesk-plus-remote-code-execution"},{"cve":"CVE-2021-37415","cvss":9.8,"slug":"cve-2021-37415-zoho-manageengine-servicedesk-authentication-bypass-vulnerability","title":"Zoho ManageEngine ServiceDesk Authentication Bypass Vulnerability","severity":"critical","exploited":true,"published_at":"2021-12-01T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2021-37415-zoho-manageengine-servicedesk-authentication-bypass-vulnerability"},{"cve":"CVE-2021-40539","cvss":9.8,"slug":"cve-2021-40539-zoho-manageengine-adselfservice-plus-authentication-bypass","title":"Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability","severity":"critical","exploited":true,"published_at":"2021-11-03T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2021-40539-zoho-manageengine-adselfservice-plus-authentication-bypass"},{"cve":"CVE-2020-10189","cvss":9.8,"slug":"cve-2020-10189-zoho-manageengine-desktop-central-file-upload-vulnerability","title":"Zoho ManageEngine Desktop Central File Upload Vulnerability","severity":"critical","exploited":true,"published_at":"2021-11-03T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2020-10189-zoho-manageengine-desktop-central-file-upload-vulnerability"},{"cve":"CVE-2019-8394","cvss":7.5,"slug":"cve-2019-8394-zoho-manageengine-servicedesk-plus-sdp-file-upload-vulnerability","title":"Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability","severity":"critical","exploited":true,"published_at":"2021-11-03T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2019-8394-zoho-manageengine-servicedesk-plus-sdp-file-upload-vulnerability"},{"cve":"CVE-2022-28810","cvss":6.8,"slug":"cve-2022-28810-zoho-manageengine-adselfservice-plus-remote-code-execution","title":"Zoho ManageEngine ADSelfService Plus Remote Code Execution Vulnerability","severity":"critical","exploited":true,"published_at":"2023-03-07T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2022-28810-zoho-manageengine-adselfservice-plus-remote-code-execution"},{"cve":"CVE-2026-19599","cvss":9.9,"epss":0.0286,"slug":"cve-2026-19599-zohocorp-manageengine-opmanager-msp-versions-12-8-709-and-below","title":"Zoho ManageEngine OpManager MSP remote code execution in Notification Profile","severity":"critical","exploited":false,"published_at":"2026-09-23T13:17:27.4+00:00","url":"https://junglewise.ai/threats/cve-2026-19599-zohocorp-manageengine-opmanager-msp-versions-12-8-709-and-below"}],"generated_at":"2026-09-26T12:07:00.15149+00:00","technologies":[{"name":"Zoho ManageEngine","slug":"manageengine","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/manageengine"}]}