← Vulnerability feed

Vulnerability record · CVE-2021-44077 · published 29 November 2021

CVE-2021-44077: Zoho ManageEngine ServiceDesk Plus unauthenticated RCE

Zohocorp · Manageengine Servicedesk Plus

Zoho ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP and SupportCenter Plus contain a missing-authentication flaw (CWE-306) in a servlet handling /RestAPI URLs and the ImportTechnicians Struts action. An unauthenticated remote attacker can reach a critical function without credentials and execute code. The flaw is rated CVSS 9.8 and is listed in CISA KEV, so it warrants urgent remediation.

9.8 CVSS 3.1 Critical CISA KEV since 1 Dec 2021 EPSS 93% · top 0.2% CWE-306 · Missing authentication for critical function
9.8CVSS 3.1 base score, v2 7.5
93%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
11References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable RCE with CVSS 9.8, KEV listing and very high EPSS probability makes this an urgent patch target.

What it is

Zoho ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP and SupportCenter Plus contain a missing-authentication flaw (CWE-306) in a servlet handling /RestAPI URLs and the ImportTechnicians Struts action. An unauthenticated remote attacker can reach a critical function without credentials and execute code. The flaw is rated CVSS 9.8 and is listed in CISA KEV, so it warrants urgent remediation.

Impact

An attacker gains remote code execution on the affected server, which typically runs with the application's privileges and can lead to full compromise of the host and connected data. No user interaction or prior authentication is required.

Attack surface

Reachable over the network via HTTP requests to /RestAPI endpoints and the ImportTechnicians Struts action; the CVSS vector shows AV:N/AC:L/PR:N/UI:N, so no authentication or user interaction is needed.

Exploitation

CISA added it to KEV on 2021-12-01 with a 2021-12-15 due date, and EPSS shows a 30-day probability of 0.93298 (99.8th percentile). Public exploit code is referenced by Packet Storm, and CISA records no known ransomware campaign use.

What to do

  • Apply the vendor patches to move ServiceDesk Plus to 11306 or later, ServiceDesk Plus MSP to 10530 or later, and SupportCenter Plus to 11014 or later.
  • If patching cannot be done immediately, restrict network access to the affected instances and block external reachability of /RestAPI and Struts endpoints.
  • Place the products behind a reverse proxy or WAF with rules targeting the /RestAPI and ImportTechnicians paths.
  • Audit the affected hosts for signs of compromise and rotate credentials and secrets stored on or reachable from them.
  • Track the CISA KEV due date and confirm remediation before it lapses.

Detection

  • Monitor web logs for requests to /RestAPI paths and ImportTechnicians actions, especially from unexpected source IPs.
  • Alert on unexpected child processes spawned by the ManageEngine service (for example cmd.exe, powershell.exe, or shell interpreters).
  • Review file system and application logs for new or modified files in web-accessible directories and for unusual technician account creation.
  • Correlate outbound network connections from the ManageEngine host to unknown destinations.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-44077 to the Known Exploited Vulnerabilities catalog on 1 December 2021 as "Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 December 2021.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/165400/ManageEngine-ServiceDesk-Plus-Remote-Code-Execution.html ExploitThird Party AdvisoryVDB Entry
https://pitstop.manageengine.com/portal/en/community/topic/security-advisory-authentication-bypass-vulnerability-in-serv PatchVendor Advisory
https://pitstop.manageengine.com/portal/en/community/topic/security-advisory-for-cve-2021-44077-unauthenticated-rce-vuln Vendor Advisory
https://pitstop.manageengine.com/portal/en/community/topic/security-advisory-for-cve-2021-44077-unauthenticated-rce-vuln Vendor Advisory
https://pitstop.manageengine.com/portal/en/community/topic/security-advisory-for-cve-2021-44077-unauthenticated-rce-vuln Vendor Advisory
http://packetstormsecurity.com/files/165400/ManageEngine-ServiceDesk-Plus-Remote-Code-Execution.html ExploitThird Party AdvisoryVDB Entry
https://pitstop.manageengine.com/portal/en/community/topic/security-advisory-authentication-bypass-vulnerability-in-serv PatchVendor Advisory
https://pitstop.manageengine.com/portal/en/community/topic/security-advisory-for-cve-2021-44077-unauthenticated-rce-vuln Vendor Advisory
https://pitstop.manageengine.com/portal/en/community/topic/security-advisory-for-cve-2021-44077-unauthenticated-rce-vuln Vendor Advisory
https://pitstop.manageengine.com/portal/en/community/topic/security-advisory-for-cve-2021-44077-unauthenticated-rce-vuln Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-44077 US Government Resource

Track CVE-2021-44077 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-47966Zoho ManageEngine on-premise products RCE via SAML SSO and xmlsecMultiple Zoho ManageEngine on-premise products use Apache Santuario xmlsec 1.4.1, whose XSLT features by design leave certain security protections to…KEVEPSS 100%analysed9.8CVE-2021-37415Zoho ManageEngine ServiceDesk Plus authentication bypass via REST APIZoho ManageEngine ServiceDesk Plus before build 11302 contains an authentication bypass (CWE-306) that lets a small number of REST-API URLs be reache…KEVEPSS 100%analysed6.5CVE-2019-8394Zoho ManageEngine ServiceDesk Plus unrestricted file upload via login page customizationZoho ManageEngine ServiceDesk Plus before 10.0 build 10012 permits remote attackers to upload arbitrary files through the login page customization fe…KEVEPSS 63%analysed9.8CVE-2023-23076ManageEngine SupportCenter Plus OS command injection in schedulesManageEngine SupportCenter Plus 11 contains an OS command injection flaw reached through the Executor in Action when creating new schedules. Because …EPSS 74%analysed9.8CVE-2022-36412Zohocorp manageengine supportcenter plus improper authentication vulnerabilityIn Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass. (An API request may, in effect, be exe…EPSS 5.2%9.8CVE-2021-44526Zohocorp manageengine servicedesk plus vulnerabilityZoho ManageEngine ServiceDesk Plus before 12003 allows authentication bypass in certain admin configurations.EPSS 3.2%9.8CVE-2021-44675Zohocorp manageengine servicedesk plus msp improper authentication vulnerabilityZoho ManageEngine ServiceDesk Plus MSP before 10.5 Build 10534 is vulnerable to unauthenticated remote code execution due to a filter bypass in which…EPSS 6.5%9.8CVE-2021-31531Zohocorp manageengine servicedesk plus msp server-side request forgery (ssrf) vulnerabilityZoho ManageEngine ServiceDesk Plus MSP before 10521 is vulnerable to Server-Side Request Forgery (SSRF).EPSS 2.4%

Source: NIST National Vulnerability Database (record CVE-2021-44077), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.