ManageEngine OpManager MSP CVE-2026-19599 (CVSS 9.9): Notification Profile RCE as customer admin — WASOC 20260924001
Zoho ManageEngine OpManager MSP advisory for CVE-2026-19599: Remote Code Execution in the Notification Profile module, exploitable by a customer administrator user on the MSP Central installed server via broken access control on an API that runs commands as part of profile functionality. Vendor severity High on the advisory page; CVE.report / CNA CVSS 3.1 9.9 CRITICAL (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). Affected trains (vendor): OpManager MSP 128166–128709 (fix 128711, 14 Aug 2026); 128718–129001 (fix 129125, 13 Aug 2026); 129100–129108 and 129117–129122 (fixed 14 Aug 2026). WASOC 20260924001 (24 Sep 2026) summarises as versions 12.8.709 and below / CVSS 9.9 Critical and reports no exploitation on WA Government networks at time of writing. Fix enforces strict access control so only MSP Central Server administrators can use the sensitive APIs. Primary: ManageEngine OpManager MSP advisory; AU: WASOC 20260924001.
- Product
- Zoho ManageEngine OpManager MSP (MSP Central)
- Versions
- Affected: OpManager MSP builds through 128709 / WASOC 12.8.709 and below (see vendor build ranges); Fixed: 128711 / 129125 and later trains per advisory
- CVSS
- (CVSS 3.1 CNA / CVE.report CRITICAL); vendor advisory severity High
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H - Exploited in Australia?
- no
- Patch to
- Apply latest OpManager MSP upgrade pack to a fixed build (128711 / 129125+ per vendor ranges); restrict customer-administrator privileges on MSP Central until patched; review Notification Profile API audit logs
Primary: ManageEngine OpManager MSP — CVE-2026-19599 advisory · Vendor: ManageEngine ITOM — CVE-2026-19599 · CVE: CVE-2026-19599 · WASOC 20260924001 — ManageEngine Critical Vulnerabilities (24 Sep 2026)
