The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning that malicious actors are exploiting a critical vulnerability in ADSelfService Plus , which allows them to take control of the system.

See also: New DNS vulnerability allows for 'state-level espionage'
ADSelfService Plus is aimed at larger organizations that need a comprehensive self-service password management and login solution for Active Directory and cloud applications.
The security issue, dubbed CVE-2021-40539, is considered critical as it could allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable system.
Zoho published an announcement announcing the release of an update that fixes the bug in ADSelfService Plus.
In a weekly security alert, the company said it has “discovered indications that this vulnerability is being exploited” by malicious actors online.
See also: Hackers target their victims' internet connections
The notice from CISA clearly refers to this vulnerability, as the organization informs that “CVE-2021-40539 has been identified in online exploits.”
At this time, information about the vulnerability is scarce. A severity rating has not been calculated by the National Institute of Standards and Technology in the US, but Zoho notes that the issue is critical:
“An authentication bypass vulnerability affecting REST API URLs, which could lead to remote code execution,” the company describes it.

Organizations with ADSelfService Plus structures older than 6114 are urged to apply the latest update from the developer, using the service pack.
See also: New Hog ransomware decrypts victims' files only if they connect to its developer's Discord server
CVE-2021-40539 is the fifth critical vulnerability reported for Zoho ManageEngine ADSelfService Plus this year. The previous four are:
CVE-2021-37421- Admin portal access bypass. Bypass in Zoho ManageEngine ADSelfService Plus 6103 and later
CVE-2021-37417- CAPTCHA bypass due to improper parameter validation in Zoho ManageEngine ADSelfService Plus build 6103 and earlier
CVE-2021-33055- unauthenticated remote code execution in non-English versions affecting Zoho ManageEngine ADSelfService Plus up to 6102
CVE-2021-28958- unauthenticated remote code execution while changing password in all Zoho ManageEngine ADSelfService Plus up to 6101
