LiveActive security incident?Get immediate response
CVE Record

CVE-2021-27104: Accellion FTA 9_12_370 and earlier is affected by OS command execution via a crafted POST request to variou...

Accellion FTA 9_12_370 and earlier is affected by OS command execution via a crafted POST request to various admin endpoints. The fixed version is FTA_9_12_380 and later.

CriticalCVSS 9.8Known exploitedUpdated
Glexia's TakeHuman reviewedcritical

Security readout for executives and security teams

Plain-English summary

This is a critical Accellion FTA flaw that allowed unauthenticated network attackers to run operating-system commands through crafted POST requests to admin endpoints. Because CISA lists it as known exploited, any remaining vulnerable FTA system should be treated as an urgent breach-risk concern, not routine patching.

Executive priority

Immediate priority. Known exploitation, unauthenticated network reachability, and full confidentiality, integrity, and availability impact make this a board-level remediation and incident-review item where FTA remains deployed or was exposed historically.

Technical view

CVE-2021-27104 is CWE-78 OS command injection in Accellion FTA 9_12_370 and earlier. The CVSS 3.1 score is 9.8, with network attack vector, low complexity, no privileges, and no user interaction. The cited fixed version is FTA_9_12_380 and later.

Likely exposure

Exposure is most likely where Accellion FTA 9_12_370 or earlier is reachable over the network, especially internet-facing file transfer deployments. The source bundle does not identify other affected products or CPEs.

Exploitation context

CISA KEV confirms this CVE is known to be exploited. The source bundle describes command execution through crafted POST requests to various admin endpoints but does not provide campaign details, exploit prerequisites beyond network access, or compromise indicators.

Researcher notes

The source bundle’s affected array is generic, but the CVE description and Accellion reference identify Accellion FTA. Evidence supports version-based validation and upgrade direction. Avoid relying on exploit mechanics for testing; validate by inventory, version, exposure, and forensic review.

Mitigation direction

  • Upgrade Accellion FTA to FTA_9_12_380 or later.
  • Identify and prioritize any internet-facing Accellion FTA systems.
  • Follow Accellion and CISA guidance for remaining FTA instances.
  • If upgrade status is uncertain, restrict exposure until verified.
  • Review incident response need for any previously vulnerable public FTA instance.

Validation and detection

  • Inventory all Accellion FTA assets and record installed versions.
  • Confirm no system runs FTA 9_12_370 or earlier.
  • Check external attack surface records for exposed FTA services.
  • Review access and application logs for suspicious admin endpoint activity.
  • Document remediation evidence for vulnerability management tracking.
Prepared
Reviewed
Confidence
high
Sources
5

Michael Williams reviewed this cited source version on .

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · medium confidence lookup

CWE-78: Command execution behavior lookup

Command injection weaknesses can lead defenders to review execution techniques and command interpreter telemetry. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2021-27104 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Critical
CVSS
9.8 (3.1)
Known Exploited
Yes
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
4Source links

CISA KEV status

Status
Known exploited
Source
CISA / ADP
Date added
Not provided

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
9.8CVSS 3.1CriticalCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H3.95.9Primary CVE score

Vulnerability scoring details

Base CVSS 3.1 score

9.8Critical
CVSS 3.1 vector shape for CVE-2021-27104Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.