← Vulnerability feed

Vulnerability record · CVE-2021-40539 · published 7 September 2021

CVE-2021-40539: Zoho ManageEngine ADSelfService Plus REST API auth bypass to RCE

Zohocorp · Manageengine Adselfservice Plus

Zoho ManageEngine ADSelfService Plus version 6113 and prior contains an authentication bypass in its REST API that leads to remote code execution. Because the flaw is reachable over the network without credentials, it exposes the self-service password management server to full compromise. The record does not list specific fixed versions beyond '6113 and prior' or detail the vulnerable code path.

9.8 CVSS 3.1 Critical CISA KEV since 3 Nov 2021 Known ransomware use EPSS 99% · top 0.1% CWE-706 · CWE-706
9.8CVSS 3.1 base score, v2 7.5
99%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
7References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable RCE with a 9.8 CVSS score, KEV listing, ransomware use and near-maximum EPSS probability.

What it is

Zoho ManageEngine ADSelfService Plus version 6113 and prior contains an authentication bypass in its REST API that leads to remote code execution. Because the flaw is reachable over the network without credentials, it exposes the self-service password management server to full compromise. The record does not list specific fixed versions beyond '6113 and prior' or detail the vulnerable code path.

Impact

An unauthenticated attacker can bypass authentication and execute arbitrary code on the server, gaining control of the host and any credentials or directory data it handles.

Attack surface

Reachable over the network via the REST API with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The description does not specify which endpoint or parameter is abused.

Exploitation

Listed in CISA KEV with known ransomware campaign use and an EPSS 30-day probability of 0.9896 (99.9th percentile); public exploit code is referenced on Packet Storm. Treat as actively exploited.

What to do

  • Apply the vendor patch per the ManageEngine KB on fixing the REST API authentication bypass vulnerability.
  • If immediate patching is not possible, restrict network access to the ADSelfService Plus REST API to trusted hosts only.
  • Place the server behind a reverse proxy or WAF and block unauthenticated access to REST API paths.
  • Rotate credentials and secrets stored or processed by the server after patching, in case of prior compromise.
  • Monitor vendor advisories for updated fixed versions, since the record only states '6113 and prior'.

Detection

  • Review web and application logs for unauthenticated or anomalous requests to ADSelfService Plus REST API endpoints.
  • Hunt for unexpected child processes spawned by the ADSelfService Plus service (e.g., cmd.exe, powershell.exe, wscript.exe).
  • Monitor for outbound connections from the ADSelfService Plus host to unfamiliar external addresses.
  • Alert on file writes or new executables in web-accessible directories of the product.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-40539 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-40539 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-47966Zoho ManageEngine on-premise products RCE via SAML SSO and xmlsecMultiple Zoho ManageEngine on-premise products use Apache Santuario xmlsec 1.4.1, whose XSLT features by design leave certain security protections to…KEVEPSS 100%analysed6.8CVE-2022-28810Zoho ManageEngine ADSelfService Plus OS command injection via custom scriptZoho ManageEngine ADSelfService Plus before build 6122 lets a remote authenticated administrator run arbitrary OS commands as SYSTEM through the poli…KEVEPSS 71%analysed10.0CVE-2019-3905Zohocorp manageengine adselfservice plus server-side request forgery (ssrf) vulnerabilityZoho ManageEngine ADSelfService Plus 5.x before build 5703 has SSRF.EPSS 3.3%9.8CVE-2023-35854Zohocorp manageengine adselfservice plus missing authentication for critical function vulnerabilityZoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain controller session token for…EPSS 6.0%9.8CVE-2021-37422Zohocorp manageengine adselfservice plus sql injection vulnerabilityZoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to SQL Injection while linking the databases.EPSS 3.4%9.8CVE-2021-37423Zohocorp manageengine adselfservice plus vulnerabilityZoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to linked applications takeover.EPSS 2.8%9.8CVE-2021-37417Zohocorp manageengine adselfservice plus improper authentication vulnerabilityZoho ManageEngine ADSelfService Plus version 6103 and prior allows CAPTCHA bypass due to improper parameter validation.EPSS 4.8%9.8CVE-2021-37421Zohocorp manageengine adselfservice plus insufficient verification of data authenticity vulnerabilityZoho ManageEngine ADSelfService Plus 6103 and prior is vulnerable to admin portal access-restriction bypass.EPSS 2.5%

Source: NIST National Vulnerability Database (record CVE-2021-40539), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.