CVE-2021-40539Active Exploitation(zohocorp / manageengine_adselfservice_plus)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch zohocorp manageengine_adselfservice_plus systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution.

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2021-11-17. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-706

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • manageengine_adselfservice_plus

Threat summary

  • Active exploitation appears in 3 classified signals
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 3 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Peaked 2d ago at 1 mentions (2026-03-30); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
manageengine_adselfservice_plus

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-30: 1Mentions · 2026-03-31: 1Mentions · 2026-04-06: 1Active Exploitation · 2026-03-30: 1Active Exploitation · 2026-03-31: 1Active Exploitation · 2026-04-06: 1Patch / Workaround · 2026-04-06: 1Technical Details · 2026-03-30: 1Technical Details · 2026-03-31: 103-3003-3104-06
Signal classification1 categories
Active Exploitation
3100.0%
Referenced assets1 URL
By indicator
Full discourse3 posts
  • Patrick Roland@DeusLogica
    Active Exploitation

    🚨 CISA KEV Update | CRITICAL CISA just batched multiple Zoho ManageEngine vulnerabilities into the KEV (including CVE-2021-40539 & CVE-2020-10189). These are classic APT initial access vectors for DIB perimeters. If you're an MSSP managing Zoho for defense contractors, check your patch delta immediately. Don't wait for the compliance deadline. Source: CISA / Roland Fleet CTI #CMMC #MSSP #CVE #KEV

    Post summary

    CISA has added Zoho ManageEngine vulnerabilities CVE-2021-40539 and CVE-2020-10189 to its KEV list, indicating active exploitation and urging MSSPs to patch immediately.

    01000137
    314 followersView on X
  • Patrick Roland@DeusLogica
    Active Exploitation

    ⚠️ CISA KEV UPDATE | high confidence CVE-2021-40539 added to CISA KEV Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution. ACTIVE EXPLOITATION CONFIRMED ATT&CK: Exploit Public-Facing Application (T1190) Source: CISA KEV | Reliability: A Link: https://nvd.nist.gov/vuln/detail/CVE-2021-40539 #CVE #CISA #KEV #threatintel #infosec

    Post summary

    CISA KEV update confirms CVE-2021-40539 is being actively exploited, with REST API authentication bypass allowing remote code execution.

    1000038
    311 followersView on X
  • Patrick Roland@DeusLogica
    Active Exploitation

    ⚠️ CISA KEV UPDATE | high confidence CVE-2021-40539 added to CISA KEV Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution. ACTIVE EXPLOITATION CONFIRMED ATT&CK: Exploit Public-Facing Application (T1190) Source: CISA KEV | Reliability: A Link: https://nvd.nist.gov/vuln/detail/CVE-2021-40539 #CVE #CISA #KEV #threatintel #infosec

    Post summary

    The CISA KEV update confirms active exploitation of CVE‑2021‑40539, a REST API authentication bypass that allows remote code execution in Zoho ManageEngine ADSelfService Plus.

    0000037
    306 followersView on X
CPE platform detail10 entries

10 of 10 entries

PartVendorProductVersionTarget SWTarget HW
Appzohocorpmanageengine_adselfservice_plus---
Appzohocorpmanageengine_adselfservice_plus6.1--
Appzohocorpmanageengine_adselfservice_plus6.1--
Appzohocorpmanageengine_adselfservice_plus6.1--
Appzohocorpmanageengine_adselfservice_plus6.1--
Appzohocorpmanageengine_adselfservice_plus6.1--
Appzohocorpmanageengine_adselfservice_plus6.1--
Appzohocorpmanageengine_adselfservice_plus6.1--
Appzohocorpmanageengine_adselfservice_plus6.1--
Appzohocorpmanageengine_adselfservice_plus6.1--

Explore more