CVE-2021-44077

unknown KEV
Published 2021-12-01 · Modified 2021-12-01
CVSS v3
CVSS v2
VIR risk
1.5

Description

Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution

CISA KEV

Vendor
Zoho
Product
ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus
Due date
2021-12-15

Predictions

Exploit likelihood
99%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cisa-kev — https://nvd.nist.gov/vuln/detail/CVE-2021-44077

Exploits

References

Verify integrity in audit chain (admin only). AS-IS.