CVE-2021-30116Active Exploitation(kaseya / vsa_agent)

LOWCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for kaseya vsa_agent systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page where the clients for the installation can be downloaded. The default URL for this page is https://x.x.x.x/dl.asp When an attacker download a client for Windows and installs it, the file KaseyaD.ini is generated (C:\Program Files (x86)\Kaseya\XXXXXXXXXX\KaseyaD.ini) which contains an Agent_Guid and AgentPassword This Agent_Guid and AgentPassword can be used to log in on dl.asp (https://x.x.x.x/dl.asp?un=840997037507813&pw=113cc622839a4077a84837485ced6b93e440bf66d44057713cb2f95e503a06d9) This request authenticates the client and returns a sessionId cookie that can be used in subsequent attacks to bypass authentication. Security issues discovered --- * Unauthenticated download page leaks credentials * Credentials of agent software can be used to obtain a sessionId (cookie) that can be used for services not intended for use by agents * dl.asp accepts credentials via a GET request * Access to KaseyaD.ini gives an attacker access to sufficient information to penetrate the Kaseya installation and its clients. Impact --- Via the page /dl.asp enough information can be obtained to give an attacker a sessionId that can be used to execute further (semi-authenticated) attacks against the system.

3.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2021-11-17. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-522

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vsa_agent
  • vsa_server

Threat summary

  • Active exploitation appears in 2 classified signals
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Technical details provided in 1 signal
  • Peaked 1d ago at 1 mentions (2026-03-09); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
vsa_agentvsa_server

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-09: 1Mentions · 2026-04-18: 1Active Exploitation · 2026-03-09: 1Active Exploitation · 2026-04-18: 1Technical Details · 2026-04-18: 103-0904-18
Signal classification1 categories
Active Exploitation
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • David@davidsheyi
    Active Exploitation

    2/ Recent examples include the Kaseya VSA attack, which leveraged a zero-day vulnerability, CVE-2021-30116, affecting 1,500 businesses. #ThreatIntel #DataBreach

    Post summary

    The post confirms that CVE‑2021‑30116 was actively exploited in the Kaseya VSA attack, impacting 1,500 businesses.

    10000106
    556 followersView on X
  • CTIWatch@ctiwatchcloud
    Active Exploitation

    🚨 [HIGH] Active exploitation detected: CVE-2021-30116 Exploit in the wild confirmed for CVE-2021-30116 (CVSS null). Kaseya Virtual System/Server Administrator (VSA) contains an information disclosure vuln... 🔗 http://ctiwatch.cloud/alerts #ZeroDay #ExploitInWild #CyberSecurity

    Post summary

    The post reports that CVE-2021-30116 is actively exploited in the wild against Kaseya VSA, exposing an information disclosure flaw. No PoC, tool, or patch details are provided.

    0000098
    5.6K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appkaseyavsa_agent---
Appkaseyavsa_server---

Explore more