H-ISAC TLP White Vulnerability: Zoho Releases Security Advisory for ManageEngine Desktop Central and Desktop Central MSP

December 7, 2021

Zoho has released a security advisory to address an authentication bypass vulnerability (CVE-2021-40539) in ManageEngine Desktop Central and Desktop Central MSP. An attacker could exploit this vulnerability to take control of an affected system. According to Zoho, this vulnerability is being actively exploited in the wild.

The United States (US) Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review the and the Zoho  

and   security advisories and apply the recommended mitigations immediately.

The Health-ISAC Threat Operations Center (TOC) also recommends users and administrators to review previous US Coast Guard Cyber Command (CGCYBER), National Security Agency (NSA), CISA, and Federal Bureau of Investigation (FBI) joint alerts that have been published in this intelligence portal, including and .

View the detailed report below. 

For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact:

John Riggi

Senior Advisor for Cybersecurity and Risk, AHA

jriggi@aha.org

(O) +1 202 626 2272