Vulnerability record · CVE-2021-37918 · published 7 October 2021
CVE-2021-37918: Zoho ManageEngine ADManager Plus unrestricted file upload RCE
Zohocorp · Manageengine Admanager Plus
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload, which leads to remote code execution. The flaw is rated CVSS 3.1 9.8 (critical) with a network vector and no privileges or user interaction required, so an exposed instance is directly at risk.
Description
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or interaction required and a very high EPSS score make this a top-priority patch despite no KEV listing.
What it is
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload, which leads to remote code execution. The flaw is rated CVSS 3.1 9.8 (critical) with a network vector and no privileges or user interaction required, so an exposed instance is directly at risk.
Impact
An attacker can upload a file of their choosing and execute code on the server, gaining full control of the ADManager Plus host and any credentials or directory data it handles.
Attack surface
Reachable over the network via the web interface (AV:N, PR:N, UI:N); no authentication or user interaction is required per the CVSS vector, though the record does not name the specific upload endpoint.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented, but EPSS is 0.73648 (99.4th percentile), indicating a high likelihood of exploitation activity; references are only vendor product and release-note pages.
What to do
- Upgrade ADManager Plus to version 7111 or later per the vendor release notes.
- If immediate patching is not possible, restrict network access to the ADManager Plus web interface to trusted management networks.
- Enforce authentication and review upload handling on any internet-facing deployment.
- Monitor the vendor advisory page for further updates and apply them promptly.
Detection
- Alert on file writes to ADManager Plus web or upload directories, especially executable extensions.
- Monitor for unexpected child processes spawned by the ADManager Plus service or its web server.
- Review web logs for POST requests to upload endpoints from untrusted sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.manageengine.com | Product |
| https://www.manageengine.com/products/ad-manager/release-notes.html#7111 | Release NotesVendor Advisory |
| https://www.manageengine.com | Product |
| https://www.manageengine.com/products/ad-manager/release-notes.html#7111 | Release NotesVendor Advisory |
Track CVE-2021-37918 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-37918), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.