# Data Exposure Vulnerability — CVE-2026-76980
**Severity:** High
**CVE ID:** CVE-2026-76980
| Product name | Affected Version(s) | Fixed Version(s) | Fixed On |
|---|---|---|---|
| OpManager
OpManager Enterprise Edition
OpManager Nexus
OpManager Nexus Enterprise Edition
Firewall Analyzer | 12.8.709 and below | 12.8.710 and above* | 14-08-2026 |
| OpManager
OpManager Enterprise Edition
OpManager Nexus
OpManager Nexus Enterprise Edition
Firewall Analyzer | 12.8.718 to 12.9.122 | 12.9.124 and above* | 20-08-2026 |
**Note:** This security vulnerability is applicable only for users of Firewall Analyzer, and for OpManager/Enterprise Edition/Nexus users with the Firewall Analyzer Plugin enabled.
## Details
Firewall Analyzer's syslog collector previously accepted incoming syslog datagrams and used the source host information to update the device IP associated with a monitored firewall. This could cause the product to consider an attacker-controlled host for a subsequent CLI configuration connection. This issue has now been fixed.
## Impact
A remote attacker who can send UDP traffic to the syslog listener could cause Firewall Analyzer to establish a CLI configuration session to a malicious host, exposing stored credentials for a managed firewall to an unauthorized party.
## Fix
Firewall Analyzer no longer uses the syslog source host for CLI configuration connections. The product continues to use the original IP address configured when the device credentials was added.
## Steps to Upgrade
1. Download the latest upgrade pack from [here](https://www.manageengine.com/network-monitoring/service-packs.html).
2. Apply the latest build to your existing product installation as per the upgrade pack instructions provided in the above step.
## Source and Acknowledgements
This vulnerability was reported by **qquynh**.
Kindly contact our product support teams for further details, at the email address mentioned below:
- OpManager: [opmanager-support@manageengine.com](mailto:opmanager-support@manageengine.com)