ZeroHour

CVE-2021-27104

KEV ransomwaremoderate

Unauthenticated OS Command Injection in Accellion FTA Admin Endpoints

CISA: Accellion FTA OS Command Injection Vulnerability

CVSS 3.1
9.8 critical
EPSS
57%p99
Published
()
KEV added
AI analysis

CVE-2021-27104 is an OS command injection flaw (CWE-78) in Accellion's File Transfer Appliance (FTA), affecting versions 9_12_370 and earlier. It is triggered by sending a crafted POST request to various admin endpoints, and the CVSS vector (no privileges, no user interaction, network-accessible) indicates it can be exploited by an unauthenticated remote attacker. Successful exploitation yields full OS command execution on the appliance, giving the attacker control sufficient for data theft, web shell deployment, and follow-on ransomware/extortion operations. Organizations running Accellion FTA appliances — typically deployed as internet-facing large-file transfer endpoints by enterprises, government agencies, and universities — are affected. The flaw is being actively exploited in the wild: it was added to CISA's KEV catalog on 2021-11-03 with known ransomware use (notably the Clop/FINEST data-theft extortion campaign, including the breach of security firm Qualys), and it carries a high EPSS score of 56.7% (99th percentile). The fixed version is FTA_9_12_380 and later.

What to do: Upgrade Accellion FTA to version FTA_9_12_380 or later per vendor instructions; the flaw is on CISA's KEV list with known ransomware use, so patching is urgent for internet-facing appliances. Until patched, restrict or firewall access to FTA admin endpoints from the internet, and review logs and the appliance for signs of command injection or web shell (e.g., DEWMODE-related) compromise given the active data-theft extortion campaign.

Affected
Accellion FTA (File Transfer Appliance)FTA 9_12_370 and earlier (fixed in FTA_9_12_380 and later)
Estimated exposure
moderate≈1,000-10,000 internet-exposed FTA appliances (enterprise appliance with a customer base in the low thousands of organizations) — Accellion FTA was an on-premises appliance deployed by a few thousand enterprises, agencies, and universities as internet-facing file transfer endpoints (the 2021 Clop extortion campaign alone hit dozens of named FTA users), so the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Accellion FTA 9_12_370 and earlier is affected by OS command execution via a crafted POST request to various admin endpoints. The fixed version is FTA_9_12_380 and later.

CISA Known Exploited Vulnerability
Affected
Accellion FTA
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
accellion
Products
fta
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news