ManageEngine Applications Manager CVE-2026-86708 (CVSS 10.0): GCP service-account key in installer — WASOC 20260924001
Zoho ManageEngine Applications Manager advisory for CVE-2026-86708 (Critical; fixed 08 September 2026): the installer included a Google Cloud service-account private key with broader-than-required permissions used for push notifications. An unauthenticated attacker who obtained the public installer could extract and misuse the key to impersonate the service account and access or modify associated cloud resources (application data, project configuration, storage, messaging, or other GCP services beyond push). Affected: version 182200 and below. Fixed: 182300 and above; also 181104–181109 and 182001–182009 trains per vendor. Fix replaces the key with a new encrypted key scoped to push-notification permissions — upgrade via service pack. CVE.report / CNA CVSS 3.1 10.0 CRITICAL (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N). WA SOC advisory 20260924001 (24 Sep 2026) groups this with two other ManageEngine criticals and states no exploitation observed on WA Government networks at time of writing. Primary: ManageEngine Applications Manager security-updates page; AU: WASOC 20260924001.
- Product
- Zoho ManageEngine Applications Manager
- Versions
- Affected: 182200 and below; Fixed: 182300+ (also 181104–181109, 182001–182009 per vendor)
- CVSS
- (CVSS 3.1 CNA / CVE.report CRITICAL)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N - Exploited in Australia?
- no
- Patch to
- Upgrade Applications Manager to 182300+ (or listed fixed trains) via vendor service pack; treat any previously distributed installer copies as potentially key-bearing; rotate/revoke any GCP service accounts tied to Applications Manager push if exposure is suspected
Primary: ManageEngine Applications Manager — CVE-2026-86708 security update · Vendor: ManageEngine — Applications Manager CVE-2026-86708 · CVE: CVE-2026-86708 · WASOC 20260924001 — ManageEngine Critical Vulnerabilities (24 Sep 2026)
