November 3, 2021 · Applied Cybernetics Group
CVE-2021-40539 — Zoho ManageEngine
known ransomware use
Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability
- Added to KEV
2021-11-03- Federal due date
2021-11-17- Vendor
- Zoho
- Product
- ManageEngine
- EPSS
- 100.0th percentile (score 0.944, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Known
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2021-40539
CISA short description
Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution.
Required action
Apply updates per vendor instructions.