← KEV catalog
CISA known exploited vulnerability

CVE-2021-40539

Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability

SOURCE FACT

Zoho · ManageEngine

Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution.

Required action

Apply updates per vendor instructions.

CISA notes

https://nvd.nist.gov/vuln/detail/CVE-2021-40539

View source evidence →

CHECK YOUR OUTSIDE-IN INVENTORY

Could this product be present?