Vulnerability
Published 2026-09-23
Verified 2026-09-27

ManageEngine OpManager MSP CVE-2026-19599 (CVSS 9.9): Notification Profile RCE as customer admin — WASOC 20260924001

Zoho ManageEngine OpManager MSP advisory for CVE-2026-19599: Remote Code Execution in the Notification Profile module, exploitable by a customer administrator user on the MSP Central installed server via broken access control on an API that runs commands as part of profile functionality. Vendor severity High on the advisory page; CVE.report / CNA CVSS 3.1 9.9 CRITICAL (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). Affected trains (vendor): OpManager MSP 128166–128709 (fix 128711, 14 Aug 2026); 128718–129001 (fix 129125, 13 Aug 2026); 129100–129108 and 129117–129122 (fixed 14 Aug 2026). WASOC 20260924001 (24 Sep 2026) summarises as versions 12.8.709 and below / CVSS 9.9 Critical and reports no exploitation on WA Government networks at time of writing. Fix enforces strict access control so only MSP Central Server administrators can use the sensitive APIs. Primary: ManageEngine OpManager MSP advisory; AU: WASOC 20260924001.

Product
Zoho ManageEngine OpManager MSP (MSP Central)
Versions
Affected: OpManager MSP builds through 128709 / WASOC 12.8.709 and below (see vendor build ranges); Fixed: 128711 / 129125 and later trains per advisory
CVSS
(CVSS 3.1 CNA / CVE.report CRITICAL); vendor advisory severity High
Exploited in Australia?
no
Patch to
Apply latest OpManager MSP upgrade pack to a fixed build (128711 / 129125+ per vendor ranges); restrict customer-administrator privileges on MSP Central until patched; review Notification Profile API audit logs

Primary: ManageEngine OpManager MSP — CVE-2026-19599 advisory · Vendor: ManageEngine ITOM — CVE-2026-19599 · CVE: CVE-2026-19599 · WASOC 20260924001 — ManageEngine Critical Vulnerabilities (24 Sep 2026)

vulnerabilities australia cloud network