ddi_central vulnerabilities
CVEs whose affected-version data names the ddi_central package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-12269High· 8.8Authenticated File Write to RCE via keepalived in DDI Central
Zohocorp ManageEngine DDI Central 6.2.0 build below 6201 had a Keepalived configuration injection vulnerability in the HA configuration workflow. This issue could allow an authenticated operator-level user to modify the Keepalived config…
CVE-2026-12268High· 8.8Authenticated PowerShell Injection leads to RCE
ManageEngine DDI Central versions below 6201 are vulnerable to PowerShell command injection in Windows DNS SPF/TXT record push leading to remote code execution.
CVE-2026-12267High· 7.2Authenticated PowerShell Injection in DNS Query Resolution Policy leads to RCE
ManageEngine DDI Central versions below 6201 are vulnerable to Command injection in Windows DNS Query Resolution Policy name field leading to remote code execution.