EXPOSURES › CVE-2021-40539
CVE-2021-40539
CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
⚡ RCE
◐ ZERO-DAY
⌖ EXPLOITED IN THE WILD
SHAME 90/100
ransomwarerceexploited-in-wildunpatched
Zoho's ManageEngine ADSelfService Plus exposed via unpatched RCE flaw exploited in the wild
Zoho ManageEngine ADSelfService Plus suffered an unpatched remote code execution vulnerability that was actively exploited by ransomware, indicating a severe lapse in security practices.
Shame score — Active exploitation by ransomware and a pattern of unpatched vulnerabilities in Zoho's product line
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
PLAYERS IMPLICATED
DESCRIPTION
Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution.
SENTIMENT · TRUSTED SOURCES
synthesis
severe-fallout
-0.60
Vulnerability allows remote code execution via authentication bypass, representing a critical security failure with severe implications for enterprise environments relying on the product.
Critical vulnerability allowing remote code execution via authentication bypass in REST API URLs, indicating a severe security flaw in the product.
"Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution."
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.