PatchSiren cyber security CVE debrief
CVE-2021-44077 Zoho CVE debrief
CVE-2021-44077 is a Zoho ManageEngine ServiceDesk Plus / SupportCenter Plus remote code execution vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2021-12-01. Because it is in KEV, organizations should treat it as an urgent patching issue and follow vendor update guidance immediately.
- Vendor
- Zoho
- Product
- ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus
- CVSS
- Unknown
- CISA KEV
- Listed
- Original CVE published
- 2021-12-01
- Original CVE updated
- 2021-12-01
- Advisory published
- 2021-12-01
- Advisory updated
- 2021-12-01
Who should care
Administrators and security teams responsible for Zoho ManageEngine ServiceDesk Plus (SDP) and SupportCenter Plus, especially any internet-facing or broadly accessible deployments. Incident response and vulnerability management teams should also prioritize it because CISA lists the flaw as known exploited.
Technical summary
The available official records identify CVE-2021-44077 as a remote code execution vulnerability affecting Zoho ManageEngine ServiceDesk Plus / SupportCenter Plus. The CISA KEV entry states that affected users should apply updates per vendor instructions. No additional technical details were supplied in the corpus here, so this summary is limited to the official classification and mitigation guidance.
Defensive priority
Urgent. CISA’s Known Exploited Vulnerabilities catalog indicates this issue is being actively exploited, so remediation should be prioritized ahead of routine patch cycles.
Recommended defensive actions
- Apply updates per vendor instructions as directed in the CISA KEV entry.
- Confirm whether any ManageEngine ServiceDesk Plus or SupportCenter Plus instances exist in the environment.
- Prioritize exposed or production systems for immediate remediation.
- Review relevant logs and alerts for signs of unauthorized activity around the affected services.
- If patching is delayed, reduce exposure by limiting access to the application to trusted networks and administrators only.
Evidence notes
This debrief is based only on the supplied official sources: the CISA KEV JSON entry, the CVE record link, and the NVD detail link. The KEV record identifies the product family, classifies the issue as a remote code execution vulnerability, lists it as known exploited, and sets a due date of 2021-12-15 for applying updates per vendor instructions. No CVSS score was provided in the supplied data.
Sources and references
Verified primary and authoritative sources
-
CVE-2021-44077 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2021-44077
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2021-44077 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2021-44077
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
-
CISA Known Exploited Vulnerabilities catalog
Publisher, destination, and source semantics verified
URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
cisa_kev
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.