CVE-2026-92905: Denial of Service Vulnerability
ZohoCorp ManageEngine EventLog Analyzer and Log360 before build 13071 were vulnerable to a DoS vulnerability that allowed attackers to crash the log collector using malformed syslog packets.
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
ManageEngine EventLog Analyzer and ManageEngine Log360 deployments running builds before 13071 are affected.
What does an attacker need to exploit this issue?
An attacker can trigger the issue by sending malformed syslog packets to the affected log collector. The supplied vector indicates this can be done over the network without privileges or user interaction.
What is the operational impact?
Successful exploitation can crash the log collector, causing a denial of service. The provided severity vector indicates no confidentiality or integrity impact.
What should be prioritized for remediation?
Upgrade affected EventLog Analyzer or Log360 installations to build 13071 or later. The provided information does not describe a workaround for systems that cannot yet be upgraded.