PT-2021-4466 · Zoho · Zoho Manageengine Adselfservice Plus

Published

2021-09-07

·

Updated

2026-04-06

·

CVE-2021-40539

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zoho ManageEngine ADSelfService Plus versions 6113 and prior.
Description Zoho ManageEngine ADSelfService Plus is susceptible to a REST API authentication bypass, potentially leading to remote code execution. This issue has been actively exploited in attacks by threat actors, including the Trigona ransomware group and APT27. Reports indicate exploitation of this vulnerability in attacks against organizations in the United States and Europe, impacting sectors like communications, water, energy, and transportation. The Red Cross experienced a breach where this vulnerability was used for initial access, allowing attackers to masquerade as legitimate users and steal data. The vulnerability stems from a missing authentication procedure. Exploitation code is publicly available.
Recommendations Update ManageEngine ADSelfService Plus to the latest version to address this issue.

Exploit

Fix

RCE

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2021-05099
CVE-2021-40539

Affected Products

Zoho Manageengine Adselfservice Plus