Vulnerability Intelligence Report
XML Injection vulnerability
CVE-2026-76979
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to an XML Injection vulnerability in the Rule Tracking Compare Policies feature.
No Active Exploit Signals
CVSS Base Score
7.7
HIGH
Exploitability:3.2
Impact Score:4.0
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-91 ↗CWE-91 XML injection (aka blind XPath injection)
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Zohocorp | ManageEngine OpManager | 0 < 12.8.710 (affected) |
| ZohoCorp | ManageEngine Firewall Analyzer | 0 < 12.8.710 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Zohocorp · Vendor · India |
| Reserved | 2026-08-20T06:00:53 |
| Published | 2026-09-23T12:22:49 |
| Last Updated | 2026-09-23T16:46:14 |
Community Chatter & Buzz