>> All posts

CVE-2021-40539: Zoho ManageEngine ADSelfService Plus auth bypass to RCE, actively exploited

The short version: CVE-2021-40539 is a REST API authentication bypass in Zoho ManageEngine ADSelfService Plus that leads to remote code execution — no valid credentials required. ADSelfService Plus is a self-service password and MFA portal that's meant to be internet-facing, which makes this an unauthenticated path straight to the server. It scores 9.8, it was exploited by APT actors, and it's in CISA's KEV catalog. Patch-and-verify. Steady hands — but move.

At a glance

FactDetail
Our severity takeCritical — in practice and on paper
CVSS v3.1 (NVD)9.8 — Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS98.96% · 99.93th percentile (2026-07-17)
In CISA KEV?Yes — added 2021-11-03, remediation due 2021-11-17
Known exploited?Yes — exploited by APT actors (subject of CISA advisory AA21-259A)
Vulnerability typeCWE-706 authentication bypass in the REST API → unauthenticated remote code execution
Requires authenticated session?No — pre-authentication
AffectedADSelfService Plus version 6113 and prior
Fixed inADSelfService Plus 6114 and later

What you need to know

ADSelfService Plus is a self-service password reset and MFA product for Active Directory — the kind of tool organizations deliberately expose to the internet so remote users can reset passwords. CVE-2021-40539 lets an attacker bypass authentication on the REST API and chain that into code execution on the server. No credential, no user interaction.

Why it's a top-priority item:

  • It's built to be internet-facing. The exposure that makes ADSelfService Plus useful is exactly the exposure this flaw abuses.
  • It's pre-authentication RCE. The bypass leads directly to running code on the host.
  • It was used by determined attackers. APT actors exploited it in targeted intrusions, and CISA issued a dedicated advisory — this is operational risk with a documented history.

How serious we see it

Critical — the 9.8 is warranted.

Unauthenticated code execution on an internet-facing identity component — one that sits next to Active Directory — is top-of-queue, and the confirmed APT exploitation removes any doubt. The bounded, reassuring part is that it's narrow and fixable: a specific product and version range, a published fix, and a quick exposure check. The catch is that this flaw was used for stealthy initial access, so if your portal was reachable, patch and hunt.

Recommendations

Straight from ManageEngine's advisory and CISA (AA21-259A):

  1. Patch now. Upgrade ADSelfService Plus to build 6114 or later.
  2. Hunt. Follow the vendor's exploit-detection guidance and review for signs of prior compromise — this was used quietly for initial access.
  3. If compromised, respond. Rebuild the host, rotate credentials and secrets, and — given the Active Directory adjacency — perform domain-wide password resets where warranted.
  4. Harden exposure. Restrict access where possible and enforce MFA; keep the management surface off the open internet.
  5. Confirm your exposure first. Verify whether you run an affected ADSelfService Plus build at all.

How BreachRisk sees it

BreachRisk discovers internet-facing ManageEngine ADSelfService Plus portals from little more than your domain, fingerprints the version, and flags exposure tied to this KEV-listed, actively exploited flaw — surfaced at the top of your results because it's in KEV. Because the affected endpoint is remotely checkable, BreachRisk can go beyond version-matching and safely confirm whether the exposed endpoint responds as vulnerable, a bounded and benign check rather than a weaponized exploit.

That outside-in, continuous view is the whole point: an internet-facing identity portal running an affected build is already mapped and ranked, so you can move straight to patch-and-verify.

References

See your cyber risk, proven.