>> All posts

CVE-2021-44515: Zoho ManageEngine Desktop Central auth bypass to RCE, actively exploited

The short version: CVE-2021-44515 is an authentication bypass in Zoho ManageEngine Desktop Central (now Endpoint Central) that leads to remote code execution — an attacker skips login and runs code on the server that manages your fleet of endpoints. It scores 9.8, it was exploited in the wild, and it's in CISA's KEV catalog. Patch-and-verify. Steady hands — but move.

At a glance

FactDetail
Our severity takeHigh — in practice and on paper
CVSS v3.1 (NVD)9.8 — Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS99.87% · 99.96th percentile (2026-07-17)
In CISA KEV?Yes — added 2021-12-10, remediation due 2021-12-24
Known exploited?Yes — actively exploited in the wild (December 2021)
Vulnerability typeAuthentication bypass → unauthenticated remote code execution (NVD lists no CWE — Unknown at time of writing)
Requires authenticated session?No — pre-authentication
AffectedDesktop Central & Desktop Central MSP: Enterprise/MSP builds 10.1.2127.17 and earlier; and builds 10.1.2128.0 through 10.1.2137.2
Fixed inBuild 10.1.2127.18 (for 10.1.2127.17 and earlier) · build 10.1.2137.3 (for 10.1.2128.0–10.1.2137.2)

What you need to know

Desktop Central (rebranded Endpoint Central) is a unified endpoint-management platform — it pushes software and patches to managed machines, which makes the server a high-value target. CVE-2021-44515 is an authentication bypass: a crafted request skips the login check and reaches functionality that leads to code execution on the server. No credentials, no interaction.

Why it's a top-priority item:

  • It's pre-authentication. The bypass is the whole attack; there's no credential to steal first.
  • The target amplifies the blast radius. An endpoint-management server can push code to every machine it manages — a compromise here can become a fleet-wide problem.
  • It was live. ManageEngine shipped an emergency fix amid observed exploitation, and CISA added it to KEV within days.

How serious we see it

High — the 9.8 is warranted.

Unauthenticated code execution on the server that controls your endpoint fleet, exploited in the wild, is top-of-queue. The bounded, reassuring part is that it's narrow and fixable: specific build ranges, published fixes, and documented indicators of compromise to check against. The catch is the usual one for an in-the-wild flaw — if your server was reachable before you patched, verify you weren't already touched, using the vendor's IoCs and detection tool.

Recommendations

Straight from ManageEngine's advisory and CISA:

  1. Patch now. Upgrade to build 10.1.2127.18 (from 10.1.2127.17 and earlier) or build 10.1.2137.3 (from 10.1.2128.0–10.1.2137.2), for both Enterprise and MSP editions.
  2. Hunt with the vendor's IoCs. Check for the documented indicators (suspicious files under the install directory, POST requests to the affected upload path) and run the exploit-detection tool.
  3. If compromised, respond. The vendor recommends full incident response — rebuild from clean media, rotate credentials and secrets, and restore from known-good backups.
  4. Harden exposure. Keep the Desktop Central / Endpoint Central console off the public internet; restrict it to trusted management networks.
  5. Confirm your exposure first. Verify whether you run an affected build at all.

How BreachRisk sees it

BreachRisk discovers internet-facing ManageEngine Desktop Central / Endpoint Central consoles from little more than your domain, fingerprints the version, and flags exposure tied to this KEV-listed, actively exploited flaw — surfaced at the top of your results because it's in KEV. Because the affected endpoint is remotely checkable, BreachRisk can go beyond version-matching and safely confirm whether the vulnerable endpoint is reachable and responding, as a bounded, benign check rather than a weaponized exploit.

That continuous, attacker's-eye view is the whole point: an endpoint-management console that shouldn't be internet-facing turns up mapped and ranked, so you can move straight to patch-and-verify.

References

See your cyber risk, proven.