CVE-2021-40539

CRITICAL(9.8)KEVRansomwareLikely Exploited

Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability

Description

CVE-2021-40539 is a critical authentication bypass vulnerability in Zoho ManageEngine ADSelfService Plus, a self-service password management and single sign-on solution. The vulnerability affects the REST API URLs in ADSelfService Plus version 6113 and prior, allowing unauthenticated attackers to bypass authentication and achieve remote code execution on the target system. CISA has added CVE-2021-40539 to its Known Exploited Vulnerabilities catalog and has confirmed its use in ransomware campaigns. With an EPSS score of 94.42% (99.98th percentile), this Zoho ManageEngine vulnerability represents one of the most actively exploited security flaws in enterprise identity management software.

KEV Information

Vendor
Zoho
Product
ManageEngine
Date Added
November 3, 2021
Due Date
November 17, 2021
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9

CWEs

Affected Products

VendorProductVersion
zohocorpmanageengine adselfservice plus< 6.1; 6.1

Multiple CVSS Assessments

Source: [email protected](Primary)
9.8
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
9.8
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

Weakness Type

CWE-706: Use of Incorrectly-Resolved Name or Reference

CWE-706 occurs when software uses a name or reference to access a resource, but the name or reference resolves to a different resource than intended. In the case of CVE-2021-40539, this weakness manifests in the REST API of Zoho ManageEngine ADSelfService Plus, where improperly resolved URL references allow attackers to bypass authentication mechanisms entirely.

Learn more: CWE-706 — Use of Incorrectly-Resolved Name or Reference

Impact Analysis

CVE-2021-40539 carries a CVSS 3.1 score of 9.8 (CRITICAL), reflecting the maximum exploitability and impact characteristics. The vulnerability is remotely exploitable over the network with low attack complexity, requires no authentication and no user interaction, making it trivially exploitable by any attacker with network access to the ADSelfService Plus instance. Successful exploitation results in complete compromise of confidentiality, integrity, and availability, granting the attacker full control over the affected system. The EPSS score of 94.42% places this vulnerability in the 99.98th percentile, indicating near-certain exploitation activity. Critically, CISA has confirmed that CVE-2021-40539 is known to be used in ransomware campaigns, significantly elevating the risk for organizations that have not applied patches.

Exploit Maturity

CVE-2021-40539 has a highly mature exploit landscape. CISA has confirmed active exploitation in the wild through its KEV catalog listing, and this vulnerability is known to be used in ransomware campaigns, making it a top-priority remediation target. Public exploit code is available via Packet Storm Security, significantly lowering the barrier to exploitation. The EPSS score of 94.42% (99.98th percentile) indicates near-certain exploitation activity, consistent with widespread targeting by both state-sponsored and cybercriminal threat actors. Federal agencies were required to remediate this vulnerability by 2021-11-17 per CISA binding operational directive.

Remediation

  1. Apply updates immediately as mandated by CISA KEV: Apply updates per vendor instructions. Upgrade Zoho ManageEngine ADSelfService Plus to a version later than build 6114 using the official patch from the ManageEngine security advisory.
  2. Verify that all instances of ADSelfService Plus (versions 6113 and prior, including all 6.1.x releases) have been updated. Check the build number in the ADSelfService Plus admin console under Settings > Product Info.
  3. If immediate patching is not possible, restrict network access to the ADSelfService Plus REST API endpoints. Block external access to port 443/8443 where ADSelfService Plus is hosted, and limit access to trusted administrative IP ranges only.
  4. Conduct a thorough forensic investigation of affected systems, reviewing web server access logs for suspicious REST API calls, checking for webshells or unauthorized files in the application directory, and scanning for indicators of compromise (IOCs) published by CISA.
  5. Implement long-term hardening measures including network segmentation of identity management infrastructure, deploying a web application firewall (WAF) in front of ADSelfService Plus, enabling comprehensive audit logging, and regularly reviewing API authentication mechanisms for similar bypass vulnerabilities.

Technical Details

CVE-2021-40539 exploits a flaw classified under CWE-706 (Use of Incorrectly-Resolved Name or Reference) in the REST API authentication layer of Zoho ManageEngine ADSelfService Plus version 6113 and prior. The vulnerability allows attackers to craft specially formatted REST API requests that bypass the authentication checks, gaining unauthorized access to privileged API endpoints. The CVSS vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H confirms that exploitation is network-based with low complexity, requires no privileges or user interaction, and results in complete compromise of the target system. Once authenticated checks are bypassed, the attacker can leverage the API to upload malicious code and achieve remote code execution with the privileges of the ADSelfService Plus service account, typically running with elevated system permissions.

Frequently Asked Questions

Is CVE-2021-40539 being actively exploited?

Yes. CVE-2021-40539 is listed in the CISA Known Exploited Vulnerabilities catalog, confirming widespread active exploitation. CISA has also confirmed that this vulnerability is known to be used in ransomware campaigns. The EPSS score of 94.42% (99.98th percentile) indicates near-certain exploitation activity.

What products are affected by CVE-2021-40539?

CVE-2021-40539 affects Zoho ManageEngine ADSelfService Plus version 6113 and all prior versions, including the 6.1.x release line. Organizations using any version of ADSelfService Plus at or below build 6113 should treat their systems as vulnerable.

How do I fix CVE-2021-40539?

Upgrade Zoho ManageEngine ADSelfService Plus to a version later than build 6114 by applying the official patch from ManageEngine. If immediate patching is not possible, restrict external access to the ADSelfService Plus REST API and conduct forensic analysis for indicators of compromise.

How severe is CVE-2021-40539?

CVE-2021-40539 has a CVSS 3.1 score of 9.8 (CRITICAL) and an EPSS score in the 99.98th percentile. It requires no authentication, is remotely exploitable, and is confirmed to be used in ransomware attacks, making it one of the most dangerous vulnerabilities in enterprise identity management software.

CVSS Score

9.8
CRITICAL(9.8)

EPSS Score

EPSS Score98.96%
EPSS Percentile99.9%

Dates

PublishedSeptember 7, 2021
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.