Vulnerability record · CVE-2021-37926 · published 7 October 2021
CVE-2021-37926: Zoho ManageEngine ADManager Plus unrestricted file upload RCE
Zohocorp · Manageengine Admanager Plus
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload, which leads to remote code execution. The flaw is rated CVSS 3.1 9.8 (critical) and maps to CWE-434. Because the product is an Active Directory management tool, compromise can expose directory and identity infrastructure.
Description
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication and no user interaction, combined with a very high EPSS score, makes this a top remediation priority despite the absence of KEV listing.
What it is
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload, which leads to remote code execution. The flaw is rated CVSS 3.1 9.8 (critical) and maps to CWE-434. Because the product is an Active Directory management tool, compromise can expose directory and identity infrastructure.
Impact
An attacker can upload a malicious file and execute code on the server, gaining the privileges of the ADManager Plus service. That position can be used to reach AD data and connected systems managed by the product.
Attack surface
The CVSS vector is AV:N/AC:L/PR:N/UI:N, so the flaw is network-reachable with no authentication and no user interaction required. The record does not specify the exact upload endpoint or parameter.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented. EPSS is 0.73648 (99.446th percentile), indicating high predicted exploitation likelihood, but the references contain only product and vendor release-note links, so no public exploit or in-the-wild confirmation is stated.
What to do
- Upgrade ADManager Plus to version 7111 or later per the vendor release notes.
- If immediate upgrade is not possible, restrict network access to the ADManager Plus web interface to trusted management networks.
- Enforce authentication and network segmentation so the service is not exposed to untrusted clients.
- Review upload handling and file-type validation settings, and monitor for unexpected executable files in upload or web directories.
- Audit the ADManager Plus service account and reduce its privileges where feasible.
Detection
- Monitor web server and ADManager Plus logs for file upload requests that result in executable or script files being written.
- Alert on new process creation spawned by the ADManager Plus service or its web server process.
- Watch for outbound connections from the ADManager Plus host to unfamiliar external addresses.
- Baseline and review files in upload, temp and web-accessible directories for unexpected additions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.manageengine.com | Product |
| https://www.manageengine.com/products/ad-manager/release-notes.html#7111 | Release NotesVendor Advisory |
| https://www.manageengine.com | Product |
| https://www.manageengine.com/products/ad-manager/release-notes.html#7111 | Release NotesVendor Advisory |
Track CVE-2021-37926 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-37926), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.