Evidence dossier

CVE-2021-44077

Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution.

Exploited in the wild (CISA KEV since Dec 1, 2021). NVD reports CVSS 3.1 9.8. EPSS estimates 93.3% exploit likelihood as of Aug 27, 2026.

88.089.1Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration.

State
PUBLISHED
Published
Nov 29, 2021
Updated
Oct 21, 2025
Evidence coverage
99%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    CVE Program

    Record text: CVE Program Container

    Inspect raw assertion
    Field
    container
    Value
    CVE Program Container
    Original evidence ↗
  3. Source dateSource date omittedFirst observed by CASCA
    mitre

    Record text: Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration.

    Inspect raw assertion
    Field
    container
    Value
    Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration.
    Original evidence ↗
  4. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability
    Original evidence ↗
  5. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 93.3% probability · 99.83th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.932980000000; percentile 0.998290000000
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date Dec 1, 2021 · first observed Jul 19, 2026

Exploit likelihood93.30%

FIRST EPSS · score date Aug 27, 2026 · 99.8th percentile · first observed Aug 27, 2026

SeverityCVSS 9.8

NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

casca-unknown-reasons-v1
Exploitation statusEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Exploit likelihoodEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Severity assessmentEvidence supported

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Aug 27, 2026
Resolution
None
Affected productsSource-reported scope

The cited source assertion is retained while canonical product linkage remains open.

Revision
casca-factor-d-obligations-v1
Cutoff
Aug 27, 2026
Resolution
Resolve identity

Source comparison

Who said what

CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CVE ProgramDerivative copy
Record text

CVE Program Container

Inspect raw assertion
Field
container
Value
CVE Program Container
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
mitreOriginal assertion
Record text

Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration.

Inspect raw assertion
Field
container
Value
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration.
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA KEVOriginal assertion
Exploitation cataloged

Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

93.3% probability · 99.83th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.932980000000; percentile 0.998290000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
73Underlying assertions
3Canonical products
73Target assertions
0Constraint assertions

Grouped from 1 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

4 scope groups

mitre · source assertedn/an/aDirect source scope
Affected: n/a
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "n/a"}]
NVD CPE · APPLICATIONzohocorpmanageengine_servicedesk_plusVulnerable target · 27 assertions
Any version (unconstrained) (< 11.1); Version 11.1; Version 11.2; Version 11.3Canonical identity product-1f3b056ace85c9471413d7fc185100e741f57159b3e51768604dfc038cbaae89Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:11.1:11140:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ad69d55a-3975-4f1e-8d6f-e0074f83ccbe
  2. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:11.1:11144:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    194beecd-f877-4d28-a534-e965d69c9eb9
  3. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:11.2:11203:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 12
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    69b73464-8627-4cce-93ce-b312a9d7b35c
  4. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:11.1:11145:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8ea1d3d0-696f-4ffe-9cde-b69071fa574e
  5. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:11.1:11138:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    106a06e5-56e8-41d3-a059-7da6737dabae
  6. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:11.1:11141:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    417d6e6a-c16a-4a76-8d65-31340834233e
  7. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:11.3:11301:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 22
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    dc971e05-d69b-4688-861d-3d6357726cb6
  8. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:11.3:11303:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 24
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5fb44a07-0d2e-4fa3-8b8b-7c56c204b4be
  9. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:11.1:11143:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    207a81a8-02ef-4793-b047-46581bf7e60b
  10. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:11.3:11305:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 26
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3287b495-e4cb-4b2f-9ed5-e077ab0cdc11
  11. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:11.3:11304:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 25
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    360c0396-e928-4fcb-bad3-6246a3bcee37
  12. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:11.3:11302:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 23
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ff31050a-1cb8-48e0-bffa-4bc89538feba
  13. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:11.2:11201:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 10
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cdc33e6b-81e2-4a15-8889-2cd709cf5e45
  14. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:11.2:11200:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 9
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7d130762-4b49-4089-99a1-fefd6b76ab8f
  15. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:11.2:11206:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 15
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a2062399-67ea-4368-9629-60e4a59ddb29
  16. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:11.2:11207:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 16
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e9841b62-4c50-4a3a-8b54-bb0aec8b1aa2
  17. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:11.1:11139:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    401aead2-183d-4e55-94ad-d24a9be46d61
  18. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:11.2:11210:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 19
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    05376518-de14-45f7-9b60-f4b4cf7bd7a2
  19. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:11.2:11205:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 14
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7be9bfcc-04ab-4053-949c-b2860e7e43b5
  20. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:11.3:11300:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 21
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    188135ef-9821-4325-a34f-ab6f430f5ddc
  21. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:11.1:11142:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1a040a5b-8c2a-4557-ab5e-1427b0f1e889
  22. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:11.2:11211:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 20
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7fb2885f-308d-4aac-9cd3-53150cc81c1f
  23. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:11.2:11204:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 13
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    51839fbe-a7e1-40fd-b44b-f9c8ca62e063
  24. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 11.1
    Match ID
    816a3cce-7bd4-4d3d-984b-6bcfe3e3769e
  25. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:11.2:11208:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 17
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4d18d25f-2eef-4ae8-9c1e-183cdc621ec4
  26. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:11.2:11209:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 18
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    dee7d305-0fa5-4126-a585-4fc1162afa29
  27. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:11.2:11202:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 11
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e08a077e-b1aa-432a-b37a-aa603c8cd1fb
NVD CPE · APPLICATIONzohocorpmanageengine_servicedesk_plus_mspVulnerable target · 31 assertions
Any version (unconstrained) (< 10.5); Version 10.5Canonical identity product-0702e4eac456299998a68bb42fa65b4c68604500f849d1e9e816e8ad90e436d0Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:10.5:10500:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 28
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6ba242db-20de-4c22-9eec-e8df5c2d8260
  2. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:10.5:10528:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 56
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8edcda56-54a1-4d94-96fd-ad1064e15767
  3. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:10.5:10522:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 50
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9ee6a4eb-e22a-4b06-9c2a-bcf1ca20a2bb
  4. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:10.5:10514:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 42
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7399a6b2-b0f2-4898-ac04-e50b508ea495
  5. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:10.5:10519:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 47
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0089deee-7cc5-4ac6-a66c-f22b4e6ef2da
  6. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:10.5:10518:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 46
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    33960952-4461-4502-a2b5-364e22c96824
  7. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:10.5:10503:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 31
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    fadcf801-93e0-430b-bd14-092ace960d05
  8. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:10.5:10509:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 37
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f33a3e84-f73b-4797-8a97-3f10f77bd631
  9. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:10.5:10517:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 45
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ab7d8e3b-30c3-44c5-90b7-561f4e09830e
  10. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:10.5:10510:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 38
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    724284ca-51fe-46e8-b90e-99c53615901b
  11. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:10.5:10511:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 39
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8342a66c-4c0b-4fae-987a-276ce126724b
  12. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:10.5:10513:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 41
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7bb0cd9f-5459-44a7-9ad1-a70d3208369b
  13. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:10.5:10525:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 53
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    79283836-e9d6-4c54-9e3d-40fb586b9071
  14. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:10.5:10529:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 57
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1a3e96bb-0ef9-4dac-84eb-7496f7293d71
  15. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:10.5:10523:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 51
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1758e31c-9ad6-480f-b425-ea7776cda1f0
  16. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:10.5:10521:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 49
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9f64234b-85f7-45fe-9308-5c45f95ec4aa
  17. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:10.5:10501:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 29
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    860ebabc-b252-4c73-97c6-57a67ed94492
  18. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:10.5:10505:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 33
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9eb715ee-313b-4d62-a345-c4f7eb7c3ded
  19. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:10.5:10506:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 34
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b965016b-7584-4661-a8f3-c8ea3db1e94c
  20. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:10.5:10526:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 54
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6aa91d46-40e8-4019-b993-80cfac548f79
  21. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:10.5:10508:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 36
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    81f583c7-cb76-430a-a7ac-f3e727e0a26d
  22. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:10.5:10507:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 35
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    dcf7199b-a66e-425b-9614-d8256c4c828d
  23. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 27
    Logic
    OR
    Version bounds
    through excluding 10.5
    Match ID
    d82a926c-edd8-4540-b6d0-695a16686511
  24. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:10.5:10515:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 43
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7793c1ac-38fa-4b31-bb78-004a519dd4a2
  25. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:10.5:10524:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 52
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9506206d-1914-4fdd-ad81-5dacc07b6990
  26. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:10.5:10527:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 55
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7dfde5e2-1f3a-4c1c-9323-0025e87fa4f8
  27. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:10.5:10502:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 30
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    71e4f529-b091-4565-b024-185174483a70
  28. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:10.5:10512:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 40
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    39c638a3-c8a1-4c2a-9b8f-39339f5674ce
  29. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:10.5:10516:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 44
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7c30d050-4bdc-46e6-819e-49898ad56bfa
  30. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:10.5:10504:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 32
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    97cd568d-af18-42e7-8357-9ae2b279bee0
  31. cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:10.5:10520:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 48
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ad1a9b14-02f0-4674-9032-73778271cacb
NVD CPE · APPLICATIONzohocorpmanageengine_supportcenter_plusVulnerable target · 15 assertions
Any version (unconstrained) (< 11.0); Version 11.0Canonical identity product-e9d0464b92638f15dab2b69b3952986565864b20a9f740a73e498e8e7f4da38bLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:zohocorp:manageengine_supportcenter_plus:11.0:11013:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 72
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3f1f21d7-08e8-4637-903b-4277399c0bd7
  2. cpe:2.3:a:zohocorp:manageengine_supportcenter_plus:11.0:11005:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 64
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c371f2cd-a1f8-4ec7-8096-d61dea337d44
  3. cpe:2.3:a:zohocorp:manageengine_supportcenter_plus:11.0:11012:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 71
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5a9c0879-8ae5-4e6e-998c-e79fc418c68a
  4. cpe:2.3:a:zohocorp:manageengine_supportcenter_plus:11.0:11003:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 62
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ab196a6f-fbd8-4573-b1b2-be2b06bd1ac5
  5. cpe:2.3:a:zohocorp:manageengine_supportcenter_plus:11.0:11006:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 65
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b980a72f-53e2-4fc1-aa25-743ae8650641
  6. cpe:2.3:a:zohocorp:manageengine_supportcenter_plus:11.0:11002:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 61
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    bdd540f2-c964-40de-91ab-de726aaa82a8
  7. cpe:2.3:a:zohocorp:manageengine_supportcenter_plus:11.0:11000:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 59
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d788203d-b169-4c98-b090-b070630750df
  8. cpe:2.3:a:zohocorp:manageengine_supportcenter_plus:11.0:11007:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 66
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    68289ae6-f348-401a-be49-08889492b23b
  9. cpe:2.3:a:zohocorp:manageengine_supportcenter_plus:11.0:11001:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 60
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    846ea6ab-9588-4d9f-aebd-83b018be7362
  10. cpe:2.3:a:zohocorp:manageengine_supportcenter_plus:11.0:11009:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 68
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    34c768e0-ff5b-413d-87b2-9d09f28f95dc
  11. cpe:2.3:a:zohocorp:manageengine_supportcenter_plus:11.0:11004:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 63
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    685783db-dd06-4d9c-9e83-63449d5b60d9
  12. cpe:2.3:a:zohocorp:manageengine_supportcenter_plus:11.0:11010:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 69
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5570c5a9-a79b-48cf-b95d-3513f7b9baf7
  13. cpe:2.3:a:zohocorp:manageengine_supportcenter_plus:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 58
    Logic
    OR
    Version bounds
    through excluding 11.0
    Match ID
    791d8e77-1a6b-4739-a6e6-bf91e978144e
  14. cpe:2.3:a:zohocorp:manageengine_supportcenter_plus:11.0:11011:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 70
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b77031f5-e097-4549-bf5e-1d0718ab52b9
  15. cpe:2.3:a:zohocorp:manageengine_supportcenter_plus:11.0:11008:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 67
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a0667dc3-8315-4f2b-bab7-d1f1ca476d68

Affected-product evidence

Accepted scope and product mapping

3 canonical links · 1 source-reported links

Mapping establishedEvidence supported

vendor-76abf9127e48519ab2b0d992e528e41eff46eda7ca5b347885ae82e9e66c68ef · product-0702e4eac456299998a68bb42fa65b4c68604500f849d1e9e816e8ad90e436d0

Source class
Nvd cpe vulnerable target
Assertions
31
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
0752399c-9894-43fd-898c-66af037ad4710963715a-59e8-470c-88ad-8a62656f0e370ad9b2c1-6e4f-4ca6-8107-41e44c3316d31487dd79-72d3-4a6c-b90f-d53d7a5017f41c5e750e-328f-460b-b816-8bb19d3b95cc1d171c51-461f-4367-93a5-230ccdda6c5e288ac742-58d4-4284-8d3b-4c892c88c1a94a108097-f398-4c0c-aa5f-521d3de75f7e89d0fb0d-bd37-432e-b592-203d809b98e98af2216c-efad-45b4-87db-24ef8190f50e8c129e5c-c517-4ecf-afd7-5b4ec54f430092b07947-9dc6-46e2-ba19-6c364c6e121fa0abe997-11ed-412f-bf94-c90c8ef0d303a40b5f08-047c-45e1-bdda-7fa6d6f8f3d1a68c6a94-2617-4f2a-9f87-096d8ed011fdaf4c4e27-02e5-4cca-a6e2-7a946d093960b9e7d42b-bc4a-4f93-9a1b-9bef3fc26b0fc0756600-df5f-4989-b2a6-af30800a0ef6c32dabf8-601f-4a2c-9a4b-90e4a03853d4c3f54be3-6223-4d53-911e-5b9826f032dcc893abbd-71c1-4c77-bfbd-eb76061c0174d12445c3-39c8-4236-a007-cf1f42c24af4d2e09eb2-53d1-4c1f-b5b8-ada29101164cd7f91ae6-3258-430c-8696-59c0eb0b063add74504b-caaa-4b7a-bd2f-c5f9948b4ddbe352c76e-8e0c-4777-bc8d-2e1ca26567e8e69d5158-d69d-4dd9-a6bf-58faff099f43ed0c2b13-38e9-48ff-b607-3b2a5d7e0b4ff758338d-1c67-4b69-9bb7-d469bdd5c64efed14015-77bc-46c3-b9bd-25631733b75dff94e543-2d0d-4f34-a8f3-5ee4875664be
Mapping establishedEvidence supported

vendor-76abf9127e48519ab2b0d992e528e41eff46eda7ca5b347885ae82e9e66c68ef · product-1f3b056ace85c9471413d7fc185100e741f57159b3e51768604dfc038cbaae89

Source class
Nvd cpe vulnerable target
Assertions
27
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
052b4e05-6eb9-430b-b263-a42cb50347d809e86f06-c36e-4b4f-92ef-9f0b0ae90f49101a9a42-ba3c-4a4b-9013-84b0fd6448102cb4b0b6-171a-44a3-a788-eb3ae2de229c2e8f787c-e22a-470d-ae9a-203ab366dfe130184f1f-72b2-46e0-802e-c8226ec679a930999d53-03b6-49f1-8130-531f44a2a98b4527b8b9-5cff-4b6b-975d-089fa96f7fab6bc3ebf7-95dd-4a46-896b-7585ad3120266d2f404f-ffb8-4598-ae34-da7170f40f5e7859e21b-670a-45cd-8d68-423af59adef07cb5c108-2774-409a-8455-b3ef32160e7a8c1d41fb-9584-4818-8f54-a3329208538d8f801e08-172c-4ae4-b331-249187d2f6d196e16aef-7330-45e4-904c-cf635cc435bc9edf27c6-e135-49f3-a6cd-816c4a5e9447a29828aa-0d11-4b6f-9d90-c9015edf58a0a4dd87c6-a1bb-40c2-93bf-b2b5f6a4b6c2af4ab569-7846-41c2-b71a-893bc4a29477b5766cef-6a0d-4666-a281-7f7073e0d27dc6528df0-5f1c-4594-b297-d64a072f0badc88eebf0-75c8-488e-a121-06d3a4f13209cc799275-0bfb-4386-a6ef-0d160d45555ed16091b1-6301-4d08-944b-5270b1946870f60cd182-75df-4594-a3ff-6bcb0798ef61f82d7241-3ac0-4724-9456-f88ee2e51a27fb313dac-dd59-45c3-a3a0-f46cf15e5330
Mapping establishedEvidence supported

vendor-76abf9127e48519ab2b0d992e528e41eff46eda7ca5b347885ae82e9e66c68ef · product-e9d0464b92638f15dab2b69b3952986565864b20a9f740a73e498e8e7f4da38b

Source class
Nvd cpe vulnerable target
Assertions
15
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
189ffa86-b984-45e6-bbc0-db966c2601c53a52749b-49cd-48a1-9448-8f6aeb3796ba4e453a89-eac4-44c3-a953-13ccf8efcf00584a70c6-e7f5-46c9-a7e1-cde5e08e7be2613b353d-107e-4008-889d-986d2d756a4e66bd6cac-0aa2-4e14-846c-fa00654bf0dc73cea80e-01aa-4916-a327-5b35ef7ee69c7eb766aa-4b97-4d05-b1c7-5d87c9b5bb9980fbd4a5-b399-4c42-a4bb-3331c138ed5e92fe1330-708e-4a55-868c-17a76a284687968549e4-2f61-463b-b24a-bc7a7ab68ca897242881-8ea5-48bc-be59-df4d69e8fe8e974bfb53-6ca3-44f7-9bf6-385848802dffcaf0bb07-ac00-48c1-8039-d63c07c31382efdbe816-ca67-4382-8cca-c1dc79d9a2d1
Source-reported scopeSource-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Vendor specified only by source · Product specified only by source

Source class
Direct cve affected
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
25042f7e-e25b-4293-ac22-4e0fd96a4db0

Assessments

CVSS by origin

9.8
NVDCVSS 3.1 · role Primary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
7.5
NVDCVSS 2.0 · role Primary · priority eligiblevalid_matchAV:N/AC:L/Au:N/C:P/I:P/A:P
9.8
CVE Program sourceCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8
CISA-ADPCVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Direct CVE/CNA normalized decisions

9.8Priority eligible

CISA-ADP

CVSS 3.1 · Secondary · Independent enrichment · rank 2

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Validation
Valid match
Recomputed
9.8
Decision reason
Evidence supported
Policy
casca-direct-cvss-eligibility-v1

Assessments are retained side by side under closed precedence. Cascade never averages CVSS.

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.