S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 8, 2024

CVE-2021-40539 Scanner

Targets the REST API endpoint in ADSelfService Plus 6113 and prior; attacker bypasses authentication to execute arbitrary code remotely.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.4k
Times Used
continuous scan runs
4.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2021-40539
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Zoho ManageEngine ADSelfService Plus is a self-service password management and single sign-on solution used by IT administrators to allow users to reset passwords, unlock accounts, and manage profiles without helpdesk intervention. It is deployed across enterprises to reduce support costs and enhance security through features like multi-factor authentication and directory integration.

CVE-2021-40539 is a critical authentication bypass vulnerability in the REST API of ADSelfService Plus versions up to 6113. The flaw arises from improper validation of user-supplied input during authentication, allowing an unauthenticated attacker to bypass security checks and execute arbitrary code on the server.

Specifically, the vulnerability exists in the REST API endpoint used for user authentication. By sending specially crafted requests, an attacker can manipulate the authentication process to gain unauthorized access and then execute commands via the product's built-in scripting capabilities.

If exploited, an attacker can achieve remote code execution with system-level privileges, leading to full compromise of the affected server. This can result in data theft, ransomware deployment, lateral movement within the network, and complete disruption of operations, posing severe risks to business continuity and data integrity.

Solution Advice
  • Upgrade Zoho ManageEngine ADSelfService Plus to version 6114 or later immediately.
  • Apply the official patch provided by Zoho for CVE-2021-40539.
  • Restrict network access to the ADSelfService Plus server using firewalls and VPNs.
  • Enable multi-factor authentication (MFA) for all administrative accounts.
  • Monitor logs for suspicious REST API requests and unauthorized access attempts.
  • Implement web application firewall (WAF) rules to block exploitation patterns.
  • Conduct a thorough security audit to identify any post-exploitation activity.
  • Ensure regular backups are taken and stored offline to aid recovery.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.