← Vulnerability feed

Vulnerability record · CVE-2021-44515 · published 12 December 2021

CVE-2021-44515: Zoho ManageEngine Desktop Central authentication bypass to RCE

Zohocorp · Manageengine Desktop Central

Zoho ManageEngine Desktop Central contains an authentication bypass that allows an unauthenticated remote attacker to execute code on the server. It was exploited in the wild in December 2021, and the vendor has published fixed builds for both Enterprise and MSP editions.

9.8 CVSS 3.1 Critical CISA KEV since 10 Dec 2021 EPSS 100% · top 0.1%
9.8CVSS 3.1 base score, v2 10.0
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
7References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in the wild in December 2021. For Enterprise builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For Enterprise builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3. For MSP builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For MSP builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable remote code execution with confirmed in-the-wild exploitation, KEV listing, and near-maximum EPSS probability.

What it is

Zoho ManageEngine Desktop Central contains an authentication bypass that allows an unauthenticated remote attacker to execute code on the server. It was exploited in the wild in December 2021, and the vendor has published fixed builds for both Enterprise and MSP editions.

Impact

An attacker gains unauthenticated remote code execution on the Desktop Central server, which typically holds broad administrative control over managed endpoints.

Attack surface

Reachable over the network via the Desktop Central web interface with no authentication and no user interaction, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The record does not specify the exact vulnerable endpoint or filter.

Exploitation

Listed in CISA KEV with a 2021-12-10 due date of 2021-12-24, and EPSS 30-day probability is 0.99871 (99.96th percentile). A vendor reference is tagged Exploit, and the description states it was exploited in the wild in December 2021.

What to do

  • Upgrade Enterprise builds 10.1.2127.17 and earlier to 10.1.2127.18, and Enterprise builds 10.1.2128.0 through 10.1.2137.2 to 10.1.2137.3.
  • Upgrade MSP builds 10.1.2127.17 and earlier to 10.1.2127.18, and MSP builds 10.1.2128.0 through 10.1.2137.2 to 10.1.2137.3.
  • If patching cannot be done immediately, remove Desktop Central from direct internet exposure and restrict access to trusted management networks.
  • Review the vendor advisory for the recommended filter configuration guidance referenced in the CVE-2021-44515 page.
  • Treat the Desktop Central server as potentially compromised if it was internet-facing before patching and hunt for post-exploitation activity.

Detection

  • Search web and proxy logs for requests to Desktop Central paths that bypass authentication, focusing on the December 2021 exploitation window and any later scanning.
  • Monitor the Desktop Central server for unexpected child processes, web shells, or new files written by the application service account.
  • Alert on outbound connections from the Desktop Central host to unfamiliar external addresses, which may indicate post-exploitation tooling.
  • Audit Desktop Central logs and host telemetry for new administrative accounts or configuration changes made outside normal change windows.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-44515 to the Known Exploited Vulnerabilities catalog on 10 December 2021 as "Zoho Desktop Central Authentication Bypass Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 24 December 2021.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-44515 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-10189Zoho ManageEngine Desktop Central deserialization RCEZoho ManageEngine Desktop Central before 10.0.474 deserializes untrusted data in the getChartImage method of the FileStorage class, reachable through…KEVEPSS 100%analysed10.0CVE-2017-7213Zohocorp manageengine desktop central improper input validation vulnerabilityZoho ManageEngine Desktop Central before build 100082 allows remote attackers to obtain control over all connected active desktops via unspecified ve…EPSS 8.1%10.0CVE-2014-9371Zohocorp manageengine desktop central improper input validation vulnerabilityThe NativeAppServlet in ManageEngine Desktop Central MSP before 90075 allows remote attackers to execute arbitrary code via a crafted JSON object.EPSS 19%9.8CVE-2020-15588Zohocorp manageengine desktop central integer overflow vulnerabilityAn issue was discovered in the client side of Zoho ManageEngine Desktop Central 10.0.552.W. An attacker-controlled server can trigger an integer over…EPSS 13%9.8CVE-2020-8540Zohocorp manageengine desktop central xml external entity (xxe) vulnerabilityAn XML external entity (XXE) vulnerability in Zoho ManageEngine Desktop Central before the 07-Mar-2020 update allows remote unauthenticated users to …EPSS 13%9.8CVE-2013-7390ManageEngine DesktopCentral unrestricted JSP file upload RCEManageEngine DesktopCentral 7.x and 8.0.0 before build 80293 exposes AgentLogUploadServlet, which accepts uploaded files without restricting their ty…EPSS 75%analysed9.8CVE-2014-5007Zohocorp manageengine desktop central path traversal vulnerabilityDirectory traversal vulnerability in the agentLogUploader servlet in ZOHO ManageEngine Desktop Central (DC) and Desktop Central Managed Service Provi…EPSS 37%9.8CVE-2018-11716Zohocorp manageengine desktop central sensitive information in log file vulnerabilityAn issue was discovered in Zoho ManageEngine Desktop Central before 100230. There is unauthenticated remote access to all log files of a Desktop Cent…EPSS 14%

Source: NIST National Vulnerability Database (record CVE-2021-44515), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.