Skip to main content

CVE detail

CVE-2021-44077

Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration.

CVSS 9.8 · CriticalBuzz score 72.1KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 72.1

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 27.1 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
27.1
14 evidence mentions in the snapshot
Diversity score
20.0
7 sources across 3 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
14 source links · newest first
  • CVE-2026-22200Horizon3.ai

    osTicket PHP Filter Chain Injection Vulnerability

    exploithorizon3.aiJan 12, 2026, 9:32 PM
  • Microsoft warns of an uptick among threat actors increasingly using publicly-disclosed zero-day exploits in their attacks. According to the Digital Defense Report published by Microsoft, threat actors are increasingly leveraging publicly-disclosed zero-day vulnerabilities to target organizations worldwide. The researchers noticed a reduction in the time between the announcement of a vulnerability and the commoditization of […]

    newssecurityaffairs.comNov 5, 2022, 5:30 PM
  • A second, custom backdoor was observed being deployed in attacks on four defense contractors if the primary backdoor was removed, security researchers with Palo Alto Networks’ Unit 42 division report.

    newswww.securityweek.comFeb 28, 2022, 11:32 AM
  • Researchers provided details about a stealthy custom malware dubbed SockDetour that targeted U.S.-based defense contractors. Cybersecurity researchers from Palo Alto Networks’ Unit 42 have analyzed a previously undocumented and custom backdoor tracked as SockDetour that targeted U.S.-based defense contractors. According to the experts, the SockDetour backdoor has been in the wild since at least July 2019. Unit 42 attributes […]

    newssecurityaffairs.comFeb 26, 2022, 6:44 PM
  • SockDetour is a custom backdoor being used to maintain persistence, designed to serve as a backup backdoor in case the primary one is removed.

    vendorunit42.paloaltonetworks.comFeb 24, 2022, 2:00 PM
  • Hackers are exploiting a critical authentication bypass vulnerability in ManageEngine Desktop Central MSP, an endpoint management tool used by managed service providers (MSPs). Attacks started before ManageEngine issued a patch, so all customers are advised to check their systems for signs of exploitation using a special tool released by the developers. ManageEngine is a division […]

    newswww.csoonline.comDec 7, 2021, 11:55 AM
  • A vulnerability (CVE-2021-44515) in ManageEngine Desktop Central is being leveraged in attacks in the wild to gain access to server running the vulnerable software. About CVE-2021-44515 CVE-2021-44515 is an authentication bypass vulnerability that could be triggered by attackers by sending a specially crafted request, with the goal of achieving unauthenticated remote code execution. The issue is considered critical by the company and affects ManageEngine Desktop Central – a unified endpoint management (UEM) solution – and … More →

    newswww.helpnetsecurity.comDec 7, 2021, 10:56 AM
  • The security problems at enterprise software provider Zoho continue to multiply with confirmation of a new critical authentication bypass vulnerability — the third in four months — being exploited in the wild by advanced threat actors.

    newswww.securityweek.comDec 6, 2021, 5:17 PM
  • 6th December – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 6th December, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Check Point Research has identified ongoing campaigns in Iran using socially engineered SMS messages to infect tens of thousands of citizens’ devices. The SMS, impersonating Iranian government services, lures victims into downloading malicious […]

    vendorresearch.checkpoint.comDec 6, 2021, 4:29 PM
  • Here’s an overview of some of last week’s most interesting news, articles and interviews: Determined APT is exploiting ManageEngine ServiceDesk Plus vulnerability (CVE-2021-44077) An APT group is leveraging a critical vulnerability (CVE-2021-44077) in Zoho ManageEngine ServiceDesk Plus to compromise organizations in a variety of sectors, including defense and tech. 150+ HP multifunction printers open to attack (CVE-2021-39237, CVE-2021-39238) Over 150 HP multifunction printers (MFPs) are open to attack via two exposed physical access port vulnerabilities … More →

    newswww.helpnetsecurity.comDec 5, 2021, 9:00 AM
  • An APT group is leveraging a critical vulnerability (CVE-2021-44077) in Zoho ManageEngine ServiceDesk Plus to compromise organizations in a variety of sectors, including defense and tech. “Successful exploitation of the vulnerability allows an attacker to upload executable files and place webshells, which enable the adversary to conduct post-exploitation activities, such as compromising administrator credentials, conducting lateral movement, and exfiltrating registry hives and Active Directory files,” the Cybersecurity and Infrastructure Security Agency (CISA) warns. About CVE-2021-44077 … More →

    newswww.helpnetsecurity.comDec 3, 2021, 10:34 AM
  • U.S. CISA urges to address vulnerabilities Qualcomm, Mikrotik, Zoho and the Apache Software Foundation software. U.S. Cybersecurity and Infrastructure Security Agency (CISA) has updated its catalog of actively exploited vulnerabilities recommending federal agencies to address the flaws in Qualcomm, Mikrotik, Zoho and the Apache Software Foundation software within specific timeframes and deadlines. CISA also warns of […]

    newssecurityaffairs.comDec 2, 2021, 8:17 PM
  • The U.S. government’s cybersecurity agency has updated its catalog of “known exploited vulnerabilities” and set deadlines for federal agencies to apply fixes for security defects in software made by Qualcomm, Mikrotik, Zoho and the Apache Software Foundation.

    newswww.securityweek.comDec 2, 2021, 6:18 PM
  • A persistent and determined APT actor has expanded beyond Zoho ManageEngine ADSelfService Plus and begun an active campaign against ServiceDesk Plus.

    vendorunit42.paloaltonetworks.comDec 2, 2021, 2:00 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence