Security readout for executives and security teams
Plain-English summary
This is a critical Accellion FTA flaw that allowed unauthenticated network attackers to run operating-system commands through crafted POST requests to admin endpoints. Because CISA lists it as known exploited, any remaining vulnerable FTA system should be treated as an urgent breach-risk concern, not routine patching.
Executive priority
Immediate priority. Known exploitation, unauthenticated network reachability, and full confidentiality, integrity, and availability impact make this a board-level remediation and incident-review item where FTA remains deployed or was exposed historically.
Technical view
CVE-2021-27104 is CWE-78 OS command injection in Accellion FTA 9_12_370 and earlier. The CVSS 3.1 score is 9.8, with network attack vector, low complexity, no privileges, and no user interaction. The cited fixed version is FTA_9_12_380 and later.
Likely exposure
Exposure is most likely where Accellion FTA 9_12_370 or earlier is reachable over the network, especially internet-facing file transfer deployments. The source bundle does not identify other affected products or CPEs.
Exploitation context
CISA KEV confirms this CVE is known to be exploited. The source bundle describes command execution through crafted POST requests to various admin endpoints but does not provide campaign details, exploit prerequisites beyond network access, or compromise indicators.
Researcher notes
The source bundle’s affected array is generic, but the CVE description and Accellion reference identify Accellion FTA. Evidence supports version-based validation and upgrade direction. Avoid relying on exploit mechanics for testing; validate by inventory, version, exposure, and forensic review.
Mitigation direction
- Upgrade Accellion FTA to FTA_9_12_380 or later.
- Identify and prioritize any internet-facing Accellion FTA systems.
- Follow Accellion and CISA guidance for remaining FTA instances.
- If upgrade status is uncertain, restrict exposure until verified.
- Review incident response need for any previously vulnerable public FTA instance.
Validation and detection
- Inventory all Accellion FTA assets and record installed versions.
- Confirm no system runs FTA 9_12_370 or earlier.
- Check external attack surface records for exposed FTA services.
- Review access and application logs for suspicious admin endpoint activity.
- Document remediation evidence for vulnerability management tracking.
Public sources used
Michael Williams reviewed this cited source version on .
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CWE-78: Command execution behavior lookup
Command injection weaknesses can lead defenders to review execution techniques and command interpreter telemetry. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Open ATT&CK lookupCVE-2021-27104 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Critical
- CVSS
- 9.8 (3.1)
- Known Exploited
- Yes
- Published
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CISA KEV status
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H3.95.9Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
9.8CriticalVector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source materials
- CVE List V5 sourceCVE List V5
- https://www.accellion.com/products/fta/CVE reference · x_refsource_MISC
- https://github.com/accellion/CVEs/blob/main/CVE-2021-27104.txtCVE reference · x_refsource_MISC
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-27104CVE reference · government-resource
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
