Description
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to a Data Exposure vulnerability in the Firewall Analyzer syslog collector.
Published: 2026-09-23
Score: 7.4 High
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The vulnerability allows an attacker to read data that should be kept confidential. The problem lies in the Firewall Analyzer syslog collector, which exposes log information to unauthorized users. This is a classic information disclosure weakness that could expose system configuration details and other sensitive data, potentially enabling further attacks, but the description does not mention remote code execution or other escalation.

Affected Systems

The affected products are ZohoCorp ManageEngine Firewall Analyzer and ManageEngine OpManager, specifically all releases up to and including version 12.8.709. Users running these older versions should verify their software version and plan an upgrade.

Risk and Exploitability

The CVSS score of 7.4 indicates a high severity, classifying the vulnerability as a High Impact. Because the EPSS score is not available, the current probability of exploitation cannot be quantified, though the absence of a KEV listing suggests no actively known exploits. The likely attack vector involves accessing the syslog collector from an authenticated or vulnerable network connection, which may require an attacker to have network access to the monitoring infrastructure or possess credentials allowing such access. The vulnerability's impact is limited to data exposure; there is no evidence of further privilege escalation in the provided description.

Generated by OpenCVE AI on September 23, 2026 at 13:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update ManageEngine Firewall Analyzer and OpManager to the latest version where the syslog collector is secured
  • Disable the syslog collector feature if it is not required for your environment
  • Restore proper access controls to the logging subsystem to ensure only authorized users can retrieve logs

Generated by OpenCVE AI on September 23, 2026 at 13:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 23 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to a Data Exposure vulnerability in the Firewall Analyzer syslog collector.
Title Data Exposure vulnerability
First Time appeared Zohocorp
Zohocorp manageengine Firewall Analyzer
Zohocorp manageengine Opmanager
Weaknesses CWE-20
CPEs cpe:2.3:a:zohocorp:manageengine_firewall_analyzer:*:*:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:*:*:*:*:*:*:*:*
Vendors & Products Zohocorp
Zohocorp manageengine Firewall Analyzer
Zohocorp manageengine Opmanager
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Zohocorp Manageengine Firewall Analyzer Manageengine Opmanager
cve-icon MITRE

Status: PUBLISHED

Assigner: Zohocorp

Published:

Updated: 2026-09-23T12:38:47.861Z

Reserved: 2026-08-20T06:01:24.559Z

Link: CVE-2026-76980

cve-icon Vulnrichment

Updated: 2026-09-23T12:38:43.341Z

cve-icon NVD

Status : Received

Published: 2026-09-23T13:17:29.393

Modified: 2026-09-23T13:17:29.393

Link: CVE-2026-76980

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T13:30:05Z

Weaknesses
  • CWE-20

    Improper Input Validation