Skip to main content

CVE detail

CVE-2021-40539

Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution.

CVSS 9.8 · CriticalBuzz score 72.5KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 72.5

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 17.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
30.0
32 evidence mentions in the snapshot
Diversity score
17.5
7 sources across 2 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
32 source links · newest first
  • loits were used or suspected, the threat actors targeted vulnerabilities in common VPNs and firewalls such as Fortinet (CVE-2024-55591, CVE-2024-21762, and CVE-2019-6693), SonicWall (CVE-2024-40766), Palo Alto (CVE-2024-3400), and Citrix (CVE-2023-4966). We also observed malicious actors successfully exploit a variety of other exposed services, includi

    vendorcloud.google.comMar 16, 2026, 2:00 PM
  • Insidious Taurus, aka Volt Typhoon, is a nation-state TA attributed to the People's Republic of China. We provide an overview of their current activity and mitigations recommendations.

    vendorunit42.paloaltonetworks.comFeb 14, 2024, 10:30 PM
  • Top 12 vulnerabilities routinely exploited in 2022Help Net Security

    Cybersecurity agencies from member countries of the Five Eyes intelligence alliance have released a list of the top 12 vulnerabilities routinely exploited in 2022, plus 30 additional ones also “popular” with attackers. The top 12 “In 2022, malicious cyber actors exploited older software vulnerabilities more frequently than recently disclosed vulnerabilities and targeted unpatched, internet-facing systems. Proof of concept (PoC) code was publicly available for many of the software vulnerabilities or vulnerability chains likely facilitating exploitation … More →

    newswww.helpnetsecurity.comAug 4, 2023, 1:17 PM
  • Five Eyes government agencies have published a list of the software vulnerabilities that were most frequently exploited in malicious attacks in 2022.

    newswww.securityweek.comAug 4, 2023, 9:08 AM
  • CISA, the FBI, and NSA, along with Five Eyes cybersecurity agencies published a list of the 12 most exploited vulnerabilities of 2022. CISA, the NSA, and the FBI, in collaboration with cybersecurity authorities from Australia, Canada, New Zealand, and the United Kingdom, have published a list of the 12 most exploited vulnerabilities of 2022. The […]

    newssecurityaffairs.comAug 4, 2023, 6:30 AM
  • China-linked APT group VANGUARD PANDA, aka Volt Typhoon, was spotted observing a novel tradecraft to gain initial access to target networks. CrowdStrike researchers observed the China-linked APT group VANGUARD PANDA, aka Volt Typhoon, using a novel tradecraft to gain initial access to target networks. The Volt Typhoon group has been active since at least mid-2021 […]

    newssecurityaffairs.comJun 26, 2023, 12:55 PM
  • The National Security Agency (NSA) and Five Eyes partner agencies have identified indicators of compromise associated with a People’s Republic of China (PRC) state-sponsored cyber actor dubbed Volt Typhoon, which is using living off the land techniques to target networks across US critical infrastructure. Volt Typhoon loves living off the land The joint cybersecurity advisory provides an overview of hunting guidance and associated best practices. It includes examples of the actor’s commands and detection signatures. … More →

    newswww.helpnetsecurity.comMay 25, 2023, 11:10 AM
  • 12th December – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 12th December, please download our Threat Intelligence Bulletin. Top Attacks and Breaches The company that holds the World Cup broadcasting rights for sub-Saharan Africa has suffered a series of cyberattacks since the beginning of the tournament, targeting one of its decoding servers. The […]

    vendorresearch.checkpoint.comDec 12, 2022, 3:13 PM
  • Microsoft warns of an uptick among threat actors increasingly using publicly-disclosed zero-day exploits in their attacks. According to the Digital Defense Report published by Microsoft, threat actors are increasingly leveraging publicly-disclosed zero-day vulnerabilities to target organizations worldwide. The researchers noticed a reduction in the time between the announcement of a vulnerability and the commoditization of […]

    newssecurityaffairs.comNov 5, 2022, 5:30 PM
  • The 2022 Unit 42 Network Threat Trends Research Report includes an analysis of the CVEs most commonly exploited in 2021 and predictions for which CVEs attackers will likely focus on in the year to come.

    vendorunit42.paloaltonetworks.comJul 21, 2022, 1:00 PM
  • Cybersecurity and Infrastructure Security Agency (CISA) published a list of 2021’s top 15 most exploited software vulnerabilities Cybersecurity and Infrastructure Security Agency (CISA) published the list of 2021’s top 15 most exploited software vulnerabilities This joint Cybersecurity Advisory (CSA) was coauthored by cybersecurity agencies of the United States, Australia, Canada, New Zealand, and the United […]

    newssecurityaffairs.comApr 28, 2022, 1:49 PM
  • Global cybersecurity authorities have published a joint advisory on the 15 Common Vulnerabilities and Exposures (CVEs) most routinely exploited by malicious cyber actors in 2021. The advisory is co-authored by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), U.S. National Security Agency (NSA), U.S. Federal Bureau of Investigation (FBI), Australian Cyber Security Centre (ACSC), Canadian […]

    newswww.csoonline.comApr 28, 2022, 10:55 AM
  • The 15 most exploited vulnerabilities in 2021Help Net Security

    In 2021, threat actors aggressively exploited newly disclosed critical software vulnerabilities to hit a broad set of targets worldwide, says the latest advisory published by the US Cybersecurity and Infrastructure Security Agency. Most exploited vulnerabilities, new and old Compiled by cybersecurity authorities from the Five Eyes intelligence alliance, the list of top 15 CVEs routinely exploited by attackers in 2021 looks like this: CVE-2021-44228 (aka Log4Shell) – in Apache Log4j CVE-2021-40539 – in Zoho ManageEngine … More →

    newswww.helpnetsecurity.comApr 28, 2022, 7:48 AM
  • A second, custom backdoor was observed being deployed in attacks on four defense contractors if the primary backdoor was removed, security researchers with Palo Alto Networks’ Unit 42 division report.

    newswww.securityweek.comFeb 28, 2022, 11:32 AM
  • Researchers provided details about a stealthy custom malware dubbed SockDetour that targeted U.S.-based defense contractors. Cybersecurity researchers from Palo Alto Networks’ Unit 42 have analyzed a previously undocumented and custom backdoor tracked as SockDetour that targeted U.S.-based defense contractors. According to the experts, the SockDetour backdoor has been in the wild since at least July 2019. Unit 42 attributes […]

    newssecurityaffairs.comFeb 26, 2022, 6:44 PM
  • SockDetour is a custom backdoor being used to maintain persistence, designed to serve as a backup backdoor in case the primary one is removed.

    vendorunit42.paloaltonetworks.comFeb 24, 2022, 2:00 PM
  • One month after disclosing a data breach that affected roughly 515,000 people, the International Committee of the Red Cross (ICRC) announced that the hackers had access to its network for 70 days before the attack was discovered.

    newswww.securityweek.comFeb 17, 2022, 1:04 PM
  • The International Committee of the Red Cross (ICRC) said attackers that breached its network last month exploited a Zoho bug. The International Committee of the Red Cross (ICRC) revealed that the attack that breached its network in January was conducted by a nation-state actor that exploited a Zoho vulnerability. In January, a cyberattack on a […]

    newssecurityaffairs.comFeb 17, 2022, 8:18 AM
  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the Coast Guard Cyber Command (CGCYBER) have shared new details on in-the-wild attacks targeting a recently patched flaw in Zoho’s ManageEngine ADSelfService Plus product.

    newswww.securityweek.comNov 22, 2021, 5:49 PM
  • Security Affairs newsletter Round 340Security Affairs

    A new round of the weekly Security Affairs newsletter arrived! Every week the best security articles from Security Affairs free for you in your email box. If you want to also receive for free the newsletter with the international press subscribe here. Hundreds of thousands of fake warnings of cyberattacks sent from a hacked FBI email […]

    newssecurityaffairs.comNov 14, 2021, 8:58 AM
  • At least nine global organizations have been compromised in attacks targeting a recent vulnerability in ManageEngine ADSelfService Plus, according to a warning from researchers at Palo Alto Networks.

    newswww.securityweek.comNov 8, 2021, 5:53 PM
  • Experts warn of an ongoing hacking campaign that already compromised at least nine organizations worldwide from critical sectors by exploiting CVE-2021-40539. Cybersecurity experts from Palo Alto Networks warn of an ongoing cyberespionage campaign that has already compromised at least nine organizations worldwide from critical sectors, including defense, healthcare, and energy. Threat actors exploited a critical […]

    newssecurityaffairs.comNov 8, 2021, 10:37 AM
  • A malicious campaign against ManageEngine ADSelfService Plus used Godzilla webshells, the NGLite backdoor and KdcSponge, a credential stealer.

    vendorunit42.paloaltonetworks.comNov 8, 2021, 2:00 AM
  • So far, 2021 has proved to be somewhat of a security annus horribilis for tech giant Microsoft, with numerous vulnerabilities impacting several of its leading services, including Active Directory, Exchange, and Azure. Microsoft is no stranger to being targeted by attackers seeking to exploit known and zero-day vulnerabilities, but the rate and scale of the […]

    newswww.csoonline.comOct 18, 2021, 9:00 AM
  • Last month, the Port of Houston, one of the major US ports, was hit by a cyber attack allegedly orchestrated by a nation-state actor. One of the major US ports, the Port of Houston, revealed that it was hit by a cyber attack in August that had no impact on its systems. “The Port of […]

    newssecurityaffairs.comSep 26, 2021, 1:31 PM
  • Cyberespionage groups are exploiting a critical vulnerability patched earlier this month in ManageEngine ADSelfService Plus, a self-service password management and single sign-on (SSO) solution for Active Directory environments. The FBI, CISA and the United States Coast Guard Cyber Command (CGCYBER) urge organizations who use the product to deploy the available patch as soon as possible […]

    newswww.csoonline.comSep 20, 2021, 3:16 PM
  • Security Affairs newsletter Round 332Security Affairs

    A new round of the weekly Security Affairs newsletter arrived! Every week the best security articles from Security Affairs free for you in your email box. The Biden administration plans to target exchanges supporting ransomware operations with sanctions Threat actor has been targeting the aviation industry since at least 2018 Expert discloses details and PoC […]

    newssecurityaffairs.comSep 19, 2021, 8:14 AM
  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the Coast Guard Cyber Command (CGCYBER) have sounded the alarm over in-the-wild attacks targeting a recently disclosed vulnerability in Zoho’s ManageEngine ADSelfService Plus product.

    newswww.securityweek.comSep 17, 2021, 11:29 AM
  • The FBI, CISA, and the Coast Guard Cyber Command (CGCYBER) warn of state-sponsored attacks that are actively exploiting CVE-2021-40539 Zoho flaw. The FBI, CISA, and the Coast Guard Cyber Command (CGCYBER) warn that nation-state APT groups are actively exploiting a critical vulnerability, tracked as CVE-2021-40539, in the Zoho ManageEngine ADSelfService Plus software. ManageEngine ADSelfService Plus […]

    newssecurityaffairs.comSep 16, 2021, 10:07 PM
  • 13th September – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 13th September, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Mēris, a new distributed denial-of-service (DDos) botnet has broken a record with a 21.8 million requests-per-second attack on Russian internet company Yandex; 250,000 devices are assumed to be compromised. MyRepublic, a Singaporean […]

    vendorresearch.checkpoint.comSep 13, 2021, 2:14 PM
  • Zoho urges customers to address an authentication bypass vulnerability in its ManageEngine ADSelfService Plus that is actively exploited in the wild. Zoho has released a security patch to address an authentication bypass vulnerability, tracked as CVE-2021-40539, in its ManageEngine ADSelfService Plus. The company also warns the vulnerability is already exploited in attacks in the wild. […]

    newssecurityaffairs.comSep 9, 2021, 6:47 AM
  • Zoho has shipped an urgent patch for an authentication bypass vulnerability in its ManageEngine ADSelfService Plus alongside a warning that the bug is already exploited in attacks. Tracked as CVE-2021-40539, the security flaw is deemed critical as it could be exploited to take over a vulnerable system.

    newswww.securityweek.comSep 8, 2021, 5:34 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence