Vulnerability Intelligence Report
Sensitive data exposure
CVE-2026-86708
ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private key in the Applications Manager installer, which could allow an unauthenticated attacker to impersonate the service account and access or modify associated cloud resources.
No Active Exploit Signals
CVSS Base Score
10.0
CRITICAL
Exploitability:3.9
Impact Score:5.8
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-321 ↗CWE-321 Use of hard-coded cryptographic key
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Zohocorp | ManageEngine Applications Manager | 0 < 182300 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Zohocorp · Vendor · India |
| Reserved | 2026-09-08T10:56:01 |
| Published | 2026-09-23T13:11:31 |
| Last Updated | 2026-09-24T03:55:22 |
Community Chatter & Buzz