Two vendor-confirmed local privilege-escalation vulnerabilities affect Zohocorp’s ManageEngine Endpoint Central, an enterprise endpoint/device management product.
CVE-2026-77697: privilege escalation during JAR extraction
Per Zohocorp’s own advisory, versions below 11.4.2540.23 are vulnerable to privilege escalation during JAR extraction. CVSS 3.1 base 6.3 (medium).
CVE-2026-77699: DLL loading from an untrusted path
Per Zohocorp’s own advisory, versions below 11.5.2605.01 are vulnerable to local privilege escalation because the product loads a DLL from an untrusted path — a classic DLL-hijacking pattern, where a lower-privileged local user can plant a malicious DLL somewhere the application will load it from before the legitimate one. CVSS 3.1 base 5.0 (medium).
Fix and affected versions
Zohocorp’s own advisories confirm both are fixed: 11.4.2540.23 or later for CVE-2026-77697, and 11.5.2605.01 or later for CVE-2026-77699 — deployments should target 11.5.2605.01 or later to close both.
Confidence
Unlike several other findings in this batch, both records trace directly to Zohocorp’s own vendor advisory (not a third-party researcher submission alone), so confidence is high.
Why this matters
Both bugs require local access to exploit — they’re privilege-escalation paths for an attacker who already has some foothold on the machine, not remote-exploitable on their own. That said, endpoint management software like ManageEngine Endpoint Central runs with elevated privileges by design (it’s deployed specifically to manage other machines), making a local privilege-escalation bug in it a meaningful step in a broader attack chain: an attacker who compromises a low-privilege account on a machine running an affected Endpoint Central version can use either flaw to escalate to the elevated privileges the management agent itself holds.
Frequently Asked Questions
What are CVE-2026-77697 and CVE-2026-77699? Two local privilege-escalation vulnerabilities in Zohocorp ManageEngine Endpoint Central: one via JAR extraction (77697, versions below 11.4.2540.23), one via untrusted DLL loading (77699, versions below 11.5.2605.01).
Which version fixes these vulnerabilities? 11.4.2540.23 fixes CVE-2026-77697; 11.5.2605.01 fixes CVE-2026-77699. Use 11.5.2605.01 or later for both.
Are these vulnerabilities being actively exploited? No evidence of active exploitation has been reported as of this writing; neither is listed in CISA’s KEV catalog.
Data sourced from Zohocorp’s own ManageEngine security advisories and the National Vulnerability Database (NVD), aggregated September 2026. See more vulnerability intelligence.