# List of security vulnerabilities fixed in DDI Central This page lists security vulnerability fixes made in various releases of DDI Central and vulnerability details. Go to [ManageEngine's Security Response Center](https://www.manageengine.com/manageengine-security-response-center.html) to report vulnerabilities on ManageEngine products. To receive security advisories for DDI Central, subscribe [here](https://www.manageengine.com/security/subscribe/). | CVE / ZVE ID | Synopsis | Severity | Fixed in version | |---|---|---|---| | [CVE-2026-75869](https://www.manageengine.com/dns-dhcp-ipam/security-updates/cve-2026-75869.html) | PowerShell injection in Windows DHCP DNS settings allowing cross-cluster command execution | High | Build 6301 | | [CVE-2026-75868](https://www.manageengine.com/dns-dhcp-ipam/security-updates/cve-2026-75868.html) | Improper authorization in Windows DHCP option handling allowing cross-cluster DNS Server option changes | High | Build 6301 | | [CVE-2026-75867](https://www.manageengine.com/dns-dhcp-ipam/security-updates/cve-2026-75867.html) | Improper authorization in Windows DHCP filter-list handling allowing cross-cluster configuration changes | High | Build 6301 | | [CVE-2026-75864](https://www.manageengine.com/dns-dhcp-ipam/security-updates/cve-2026-75864.html) | Insufficient authorization in Windows DNS zone-scope API allowing unauthorized zone deletion | High | Build 6301 | | [CVE-2026-19422](https://www.manageengine.com/dns-dhcp-ipam/security-updates/cve-2026-19422.html) | Authentication bypass in Windows agent synchronization APIs leading to unauthorized DNS and DHCP modifications | High | Build 6301 | | [CVE-2026-19421](https://www.manageengine.com/dns-dhcp-ipam/security-updates/cve-2026-19421.html) | PowerShell injection in Windows DNS TXT record handling leading to remote code execution | High | Build 6301 | | [CVE-2026-19420](https://www.manageengine.com/dns-dhcp-ipam/security-updates/cve-2026-19420.html) | Insufficient zone-level authorization in DNS APIs allowing cross-tenant access and unauthorized changes | High | Build 6301 | | [CVE-2026-19419](https://www.manageengine.com/dns-dhcp-ipam/security-updates/cve-2026-19419.html) | Authenticated DHCP configuration injection leading to remote command execution | High | Build 6301 | | [CVE-2026-12572](https://www.manageengine.com/dns-dhcp-ipam/security-updates/cve-2026-12572.html) | SQL injection in HA replication username handling leading to command execution as the PostgreSQL service account | High | Build 6201 | | [CVE-2026-12573](https://www.manageengine.com/dns-dhcp-ipam/security-updates/cve-2026-12573.html) | Cisco IOS command injection via DHCP pool name leading to arbitrary commands on managed Cisco routers | High | Build 6201 | | [CVE-2026-12574](https://www.manageengine.com/dns-dhcp-ipam/security-updates/cve-2026-12574.html) | Server-side HTML/JavaScript injection in analytics PDF generation leading to local file disclosure | High | Build 6201 | | [CVE-2026-12571](https://www.manageengine.com/dns-dhcp-ipam/security-updates/cve-2026-12571.html) | Authentication bypass in password-reset verification workflow leading to account takeover | High | Build 6201 | | [CVE-2026-12269](https://www.manageengine.com/dns-dhcp-ipam/security-updates/cve-2026-12269.html) | Keepalived configuration injection through HA workflow leading to remote code execution as root | High | Build 6201 | | [CVE-2026-12264](https://www.manageengine.com/dns-dhcp-ipam/security-updates/cve-2026-12264.html) | Arbitrary file write via HA Failover Config sync upload leading to remote code execution as root | High | Build 6201 | | [CVE-2026-12268](https://www.manageengine.com/dns-dhcp-ipam/security-updates/cve-2026-12268.html) | PowerShell command injection in Windows DNS SPF/TXT record push leading to remote code execution | High | Build 6201 | | [CVE-2026-12267](https://www.manageengine.com/dns-dhcp-ipam/security-updates/cve-2026-12267.html) | Command injection in Windows DNS Query Resolution Policy name field leading to remote code execution | High | Build 6201 | | [CVE-2026-12266](https://www.manageengine.com/dns-dhcp-ipam/security-updates/cve-2026-12266.html) | LDAP bind password exposure through insufficiently protected LDAP settings API | High | Build 6201 | | [CVE-2026-12265](https://www.manageengine.com/dns-dhcp-ipam/security-updates/cve-2026-12265.html) | Insufficient access control in HA failover endpoint leading to destructive PostgreSQL database operations | High | Build 6201 | | [CVE-2024-12686](https://www.manageengine.com/dns-dhcp-ipam/security-updates/cve-2024-12686.html) | Remote command execution on Node Agent/DDI Console servers | Medium | Build 4002 | | [CVE-2024-5471](https://www.manageengine.com/dns-dhcp-ipam/security-updates/new-cve-2024-5471.html) | Unrestricted takeover of Node Agent servers | High | Build 4002 | | [CVE-2024-27311](https://www.manageengine.com/dns-dhcp-ipam/security-updates/cve-2024-27311.html) | Arbitrary file writing via directory traversal | Medium | Build 4002 |