← Vulnerability feed

Vulnerability record · CVE-2021-37926 · published 7 October 2021

CVE-2021-37926: Zoho ManageEngine ADManager Plus unrestricted file upload RCE

Zohocorp · Manageengine Admanager Plus

Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload, which leads to remote code execution. The flaw is rated CVSS 3.1 9.8 (critical) and maps to CWE-434. Because the product is an Active Directory management tool, compromise can expose directory and identity infrastructure.

9.8 CVSS 3.1 Critical EPSS 74% · top 0.5% CWE-434 · Unrestricted file upload
9.8CVSS 3.1 base score, v2 7.5
74%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with network reachability, no authentication and no user interaction, combined with a very high EPSS score, makes this a top remediation priority despite the absence of KEV listing.

What it is

Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload, which leads to remote code execution. The flaw is rated CVSS 3.1 9.8 (critical) and maps to CWE-434. Because the product is an Active Directory management tool, compromise can expose directory and identity infrastructure.

Impact

An attacker can upload a malicious file and execute code on the server, gaining the privileges of the ADManager Plus service. That position can be used to reach AD data and connected systems managed by the product.

Attack surface

The CVSS vector is AV:N/AC:L/PR:N/UI:N, so the flaw is network-reachable with no authentication and no user interaction required. The record does not specify the exact upload endpoint or parameter.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented. EPSS is 0.73648 (99.446th percentile), indicating high predicted exploitation likelihood, but the references contain only product and vendor release-note links, so no public exploit or in-the-wild confirmation is stated.

What to do

  • Upgrade ADManager Plus to version 7111 or later per the vendor release notes.
  • If immediate upgrade is not possible, restrict network access to the ADManager Plus web interface to trusted management networks.
  • Enforce authentication and network segmentation so the service is not exposed to untrusted clients.
  • Review upload handling and file-type validation settings, and monitor for unexpected executable files in upload or web directories.
  • Audit the ADManager Plus service account and reduce its privileges where feasible.

Detection

  • Monitor web server and ADManager Plus logs for file upload requests that result in executable or script files being written.
  • Alert on new process creation spawned by the ADManager Plus service or its web server process.
  • Watch for outbound connections from the ADManager Plus host to unfamiliar external addresses.
  • Baseline and review files in upload, temp and web-accessible directories for unexpected additions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-37926 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-47966Zoho ManageEngine on-premise products RCE via SAML SSO and xmlsecMultiple Zoho ManageEngine on-premise products use Apache Santuario xmlsec 1.4.1, whose XSLT features by design leave certain security protections to…KEVEPSS 100%analysed9.8CVE-2021-42002Zohocorp manageengine admanager plus vulnerabilityZoho ManageEngine ADManager Plus before 7115 is vulnerable to a filter bypass that leads to file-upload remote code execution.EPSS 7.5%9.8CVE-2021-38298Zohocorp manageengine admanager plus xml external entity (xxe) vulnerabilityZoho ManageEngine ADManager Plus before 7110 is vulnerable to blind XXE.EPSS 2.6%9.8CVE-2021-37762Zohocorp manageengine admanager plus unrestricted file upload vulnerabilityZoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file overwrite leading to remote code execution.EPSS 8.1%9.8CVE-2021-37918Zoho ManageEngine ADManager Plus unrestricted file upload RCEZoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload, which leads to remote code execution. The flaw is rated CVSS…EPSS 74%analysed9.8CVE-2021-37919Zohocorp manageengine admanager plus unrestricted file upload vulnerabilityZoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.EPSS 11%9.8CVE-2021-37920Zohocorp manageengine admanager plus unrestricted file upload vulnerabilityZoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.EPSS 11%9.8CVE-2021-37921Zohocorp manageengine admanager plus unrestricted file upload vulnerabilityZoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.EPSS 11%

Source: NIST National Vulnerability Database (record CVE-2021-37926), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.