← Back to CVE List
Vulnerability Intelligence Report
Sensitive data exposure

CVE-2026-86708

ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private key in the Applications Manager installer, which could allow an unauthenticated attacker to impersonate the service account and access or modify associated cloud resources.

No Active Exploit Signals
CVSS Base Score
10.0
CRITICAL
Exploitability:3.9
Impact Score:5.8
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-321 ↗CWE-321 Use of hard-coded cryptographic key

Affected Products & Versions

Vendor Product Affected Versions
Zohocorp ManageEngine Applications Manager 0 < 182300 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityZohocorp · Vendor · India
Reserved2026-09-08T10:56:01
Published2026-09-23T13:11:31
Last Updated2026-09-24T03:55:22

LINK COPIED TO CLIPBOARD