CVE-2026-3879Disclosure(zohocorp / manageengine_exchange_reporter_plus)

LOWCVSS 4.8 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Equipment Mailbox Details report.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • manageengine_exchange_reporter_plus

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
manageengine_exchange_reporter_plus

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-03: 2Technical Details · 2026-04-03: 204-03
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-3879 Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Equipment Mailbox Details report. https://www.cve.org/CVERecord?id=CVE-2026-3879

    Post summary

    The post provides a brief disclosure that ManageEngine Exchange Reporter Plus versions prior to 5802 are vulnerable to stored XSS in the Equipment Mailbox Details report, directing readers to the CVE record for more details.

    00010147
    56.9K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-3879 Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Equipment Mailbox Details report. https://www.cve.org/CVERecord?id=CVE-2026-3879 ----- Traducción: CVE-2026-3879 Las versiones de ManageEngine Exchange Rep… http://infoflow.cloud`

    Post summary

    Announcement of a stored‑XSS flaw in ManageEngine Exchange Reporter Plus (pre‑5802) with a CVE reference; no exploitation, PoC, or patch information provided.

    0000032
    65 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appzohocorpmanageengine_exchange_reporter_plus---
Appzohocorpmanageengine_exchange_reporter_plus5.8--
Appzohocorpmanageengine_exchange_reporter_plus5.8--
Appzohocorpmanageengine_exchange_reporter_plus5.8--

Explore more