CVE-2026-12267EPSS p89.1%

CVE-2026-12267CVE-2026-12267

Description

ManageEngine DDI Central versions below 6201 are vulnerable to Command injection in Windows DNS Query Resolution Policy name field leading to remote code execution.

Scoring

CVSS 7.2 ()
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS3.60% probability of exploitation · percentile 89.1% · 2026-10-05T12:00:23Z
Last modified2026-09-29
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.