Sep 29, 2026·5 min read·4 visits
Unauthenticated remote attackers can crash the ManageEngine log collector service by sending crafted, malformed syslog datagrams to the syslog listener port.
ZohoCorp ManageEngine EventLog Analyzer and Log360 before build 13071 were vulnerable to a denial-of-service (DoS) vulnerability that allowed unauthenticated remote attackers to crash the log collector service using malformed syslog packets.
Zoho ManageEngine EventLog Analyzer and Log360 contain a denial-of-service vulnerability in their log collector components. This component functions as a centralized syslog server that processes network logs from various enterprise assets. It listens on standard UDP and TCP ports to receive logging information in real time.
The vulnerability is exposed to the local or external network depending on how the syslog daemon is configured. Any unauthenticated network client capable of routing traffic to the syslog port can reach this parser. This wide attack surface makes the service highly susceptible to disruptions from internal or external sources.
Because the service handles raw, unstructured network input, robust validation at the packet boundary is required. The lack of proper exception handling within this boundary allows an attacker to terminate the daemon process entirely. This disrupts log aggregation capabilities across the enterprise.
The vulnerability stems from a failure to handle parsing exceptions within the syslog receiver thread pool. When a syslog packet arrives on UDP or TCP port 514, the log collector allocates a thread to process the payload. This thread attempts to parse the payload according to standard specifications like RFC 3164 or RFC 5424.
During parsing, the engine tokenizes fields such as the priority value, timestamp, hostname, and message body. If the incoming payload is malformed—such as containing non-ASCII characters in header fields, negative length values, or truncated frames—the parser generates a runtime exception. In Java, this typically manifests as an IndexOutOfBoundsException or NullPointerException during string tokenization.
Because there is no try-catch block wrapping this parsing logic, the runtime exception propagates up the call stack. The uncaught exception terminates the worker thread and, in this specific architecture, bubbles up to the main application context. The JVM then terminates the log collector service, resulting in a complete denial of service.
To understand the vulnerability, consider the structure of the packet ingestion loop before build 13071. The application reads datagrams from the network socket and passes the raw bytes directly to the parser class without boundary checks. The following pseudo-code illustrates this unsafe architecture:
// Vulnerable Code Pattern
public void processPacket(byte[] data) {
// No validation of packet structure before parsing
SyslogParser parser = new SyslogParser();
SyslogMessage msg = parser.parseRawBytes(data);
// If parseRawBytes throws a RuntimeException, the thread terminates
this.dbWriter.write(msg);
}In the patched version (Build 13071), Zoho Corp implemented robust error boundaries around the parsing operations. The execution flow is wrapped in a try-catch block that specifically handles all runtime exceptions. This prevents the exception from propagating to the parent process and ensures the thread pool remains active:
// Patched Code Pattern in Build 13071
public void processPacket(byte[] data) {
try {
if (data == null || data.length < MIN_SYSLOG_LEN) {
return; // Quick discard of trivial payloads
}
SyslogParser parser = new SyslogParser();
SyslogMessage msg = parser.parseRawBytes(data);
this.dbWriter.write(msg);
} catch (RuntimeException e) {
// Exception is caught locally, preventing service termination
Logger.error("Failed to parse syslog packet: " + e.getMessage());
}
}This structural change isolates the parsing logic of individual packets. A malformed datagram will now only trigger a logged warning and a silent discard of the corrupted input. The main service process continues executing, maintaining availability for all other legitimate log sources.
Exploitation of CVE-2026-92905 does not require authentication or complex session establishment. An attacker with network access to the syslog listener port can deliver a single malformed packet to trigger the crash. The attack is entirely self-contained within the initial datagram, requiring no multi-stage interaction.
The exploit payload is structured to violate the formatting rules expected by the parser. For example, sending a sequence of control characters or an invalid facility/severity header sequence triggers the exception. Since the listener is often run over UDP, the attacker can spoof the source IP address, complicating attribution and defensive filtering.
The following diagram illustrates the sequence of events during a successful denial-of-service attack:
Once the service enters the crashed state, it ceases to listen on the designated ports. Syslog packets transmitted by other network infrastructure components are dropped. The denial of service persists until an administrator manually restarts the service or the system executes an automated recovery policy.
The primary remediation for CVE-2026-92905 is updating the affected products to Build 13071 or later. Zoho Corp has released consolidated service packs that apply the necessary code modifications to the log collector. Administrators should download these packs from official vendor repositories and schedule an immediate update window.
When patching is delayed, organizations must implement compensating controls at the network layer. Firewalls must restrict access to the syslog listener ports (UDP and TCP 514) to a strict whitelist of known logging sources. This prevents unauthorized network actors from interacting with the vulnerable parsing engine.
Additionally, service recovery options within the operating system should be configured to automatically restart the service. While this does not prevent the exploitation attempt, it reduces the duration of the resulting outage. Administrators can configure Windows Service Manager to restart the service immediately after a failure is detected.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L| Product | Affected Versions | Fixed Version |
|---|---|---|
ManageEngine EventLog Analyzer Zoho Corp | < Build 13071 | Build 13071 |
ManageEngine Log360 Zoho Corp | < Build 13071 | Build 13071 |
| Attribute | Detail |
|---|---|
| CWE ID | CWE-248 (Uncaught Exception) |
| Attack Vector | Network |
| CVSS v3.1 Score | 5.3 (Medium) |
| Impact | Denial of Service (Availability) |
| Exploit Status | No public PoC |
| KEV Status | Not Listed |
A critical HTTP request/response smuggling vulnerability (CWE-444) exists in Citrix NetScaler ADC and Citrix NetScaler Gateway. This flaw arises from inconsistent request boundary parsing between NetScaler appliances and backend web servers, allowing remote, unauthenticated attackers to bypass security boundaries, access restricted resources, or hijack active user sessions on multiplexed TCP connections.
A high-severity Cross-Site Scripting (XSS) vulnerability in Angular server-side rendering (SSR) component allows unauthenticated attackers to execute arbitrary client-side JavaScript. The flaw is caused by a parsing discrepancy between the server-side DOM emulator, Domino, and standard client-side browser HTML5 parsers. When serializing ProcessingInstruction nodes inside raw-content fallback elements, Domino fails to escape matching ancestor closing tags, causing the client-side parser to transition out of raw-text mode prematurely and execute subsequent sibling elements as active HTML.
A validation bypass vulnerability exists in the npm package `ip-address` from version 10.2.0 to 10.5.1. The library's `Address6.isPrivate()` classifier fails to recognize the NAT64 local-use prefix range 64:ff9b:1::/48 as a restricted, private subnet. In networks implementing NAT64 routing configurations, an attacker can exploit this flaw to execute Server-Side Request Forgery (SSRF) and bypass local trust-boundary validations.
A validation bypass exists in the ip-address library prior to version 10.5.1. The Address6.isLinkLocal() method inaccurately restricted link-local classifications to the fe80::/64 subnet, failing to cover the complete RFC 4291 fe80::/10 allocation. This allows attackers to bypass SSRF filters relying on this library to safeguard local network boundaries.
An interpretation conflict in the fast-uri library allows unauthenticated remote attackers to bypass Server-Side Request Forgery filters due to inconsistent handling of malformed bracket notation in hostnames.
An authority injection vulnerability exists in the serialization components of fast-uri (versions before 2.4.6, 3.1.7, and 4.1.4) where unvalidated port components can contain authority delimiters (such as '@'). This results in host demotion to userinfo, redirection of traffic to an arbitrary attacker-controlled host, and downstream Server-Side Request Forgery (SSRF) without causing parser errors in standard clients.