criticalKEV
CVE-2021-40539
ADSelfService Plus REST API authentication bypass -> remote code execution
- Severity
- critical
- Affected product
- ManageEngine ADSelfService Plus
- Affected versions
- ManageEngine ADSelfService Plus all versions before the fix
- CISA KEV
- Listed as a known exploited vulnerability
- Added to NewScan
- 2026-08-02
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the ManageEngine ADSelfService Plus appliance and reports this CVE when the detected version falls inside the affected range below.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →