December 10, 2021 · Applied Cybernetics Group
CVE-2021-44515 — Zoho Desktop Central
Zoho Desktop Central Authentication Bypass Vulnerability
- Added to KEV
2021-12-10- Federal due date
2021-12-24- Vendor
- Zoho
- Product
- Desktop Central
- EPSS
- 100.0th percentile (score 0.943, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2021-44515
CISA short description
Zoho Desktop Central contains an authentication bypass vulnerability that could allow an attacker to execute arbitrary code in the Desktop Central MSP server.
Required action
Apply updates per vendor instructions.