← Vulnerability feed

Vulnerability record · CVE-2021-37539 · published 27 September 2021

CVE-2021-37539: Zoho ManageEngine ADManager Plus unrestricted file upload enables RCE

Zohocorp · Manageengine Admanager Plus

Zoho ManageEngine ADManager Plus before build 7111 allows unrestricted file upload, which the vendor classifies as leading to remote code execution. The flaw is network-reachable with no authentication or user interaction required, so any exposed instance is directly at risk. It matters because ADManager Plus is an Active Directory management tool, making successful exploitation a path into privileged directory infrastructure.

9.8 CVSS 3.1 Critical EPSS 93% · top 0.2% CWE-434 · Unrestricted file upload
9.8CVSS 3.1 base score, v2 7.5
93%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Zoho ManageEngine ADManager Plus before 7111 is vulnerable to unrestricted file which leads to Remote code execution.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with no authentication or interaction required, and an EPSS score near the top percentile, makes this an urgent patch for any internet- or broadly reachable deployment.

What it is

Zoho ManageEngine ADManager Plus before build 7111 allows unrestricted file upload, which the vendor classifies as leading to remote code execution. The flaw is network-reachable with no authentication or user interaction required, so any exposed instance is directly at risk. It matters because ADManager Plus is an Active Directory management tool, making successful exploitation a path into privileged directory infrastructure.

Impact

An unauthenticated attacker can upload a file of their choosing and achieve remote code execution on the ADManager Plus server. That yields code execution in the context of the application, which typically has broad access to Active Directory.

Attack surface

Reached over the network via the application's HTTP interface, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication and no user interaction are required.

Exploitation

CISA KEV does not list this CVE, but EPSS is very high at 0.92868 (99.8th percentile), indicating strong predicted exploitation activity. The references are only product and vendor advisory pages, so no public exploit or in-the-wild confirmation is documented in this record.

What to do

  • Upgrade ADManager Plus to build 7111 or later, per the vendor release notes.
  • Do not expose the ADManager Plus web interface to the internet; restrict it to trusted management networks or VPN.
  • Restrict and monitor upload directories, and block execution of uploaded files at the web server or application layer.
  • Run the service under a least-privilege account so post-exploitation access to Active Directory is limited.
  • Audit for unauthorized administrative accounts or changes in ADManager Plus and connected directory services.

Detection

  • Monitor the ADManager Plus upload endpoints for file writes with executable extensions or unexpected content types.
  • Alert on new process creation spawned by the ADManager Plus service or its web server worker processes.
  • Review web server and application logs for anomalous POST requests to upload paths from untrusted source addresses.
  • Watch for unexpected outbound connections or new scheduled tasks originating from the ADManager Plus host.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-37539 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-47966Zoho ManageEngine on-premise products RCE via SAML SSO and xmlsecMultiple Zoho ManageEngine on-premise products use Apache Santuario xmlsec 1.4.1, whose XSLT features by design leave certain security protections to…KEVEPSS 100%analysed9.8CVE-2021-42002Zohocorp manageengine admanager plus vulnerabilityZoho ManageEngine ADManager Plus before 7115 is vulnerable to a filter bypass that leads to file-upload remote code execution.EPSS 7.5%9.8CVE-2021-38298Zohocorp manageengine admanager plus xml external entity (xxe) vulnerabilityZoho ManageEngine ADManager Plus before 7110 is vulnerable to blind XXE.EPSS 2.6%9.8CVE-2021-37762Zohocorp manageengine admanager plus unrestricted file upload vulnerabilityZoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file overwrite leading to remote code execution.EPSS 8.1%9.8CVE-2021-37918Zoho ManageEngine ADManager Plus unrestricted file upload RCEZoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload, which leads to remote code execution. The flaw is rated CVSS…EPSS 74%analysed9.8CVE-2021-37919Zohocorp manageengine admanager plus unrestricted file upload vulnerabilityZoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.EPSS 11%9.8CVE-2021-37920Zohocorp manageengine admanager plus unrestricted file upload vulnerabilityZoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.EPSS 11%9.8CVE-2021-37921Zohocorp manageengine admanager plus unrestricted file upload vulnerabilityZoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.EPSS 11%

Source: NIST National Vulnerability Database (record CVE-2021-37539), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.