Cyber Resilience

CVE-2021-27101

Accellion Fta ≤ 9_12_370

CISA KEVActive ExploitationEUVD ExploitedRansomware-linked
Published
16 February 2021
Modified
03 November 2025
KEV Added
03 November 2021
Patch / advisory
CVSS Score v3.1 9.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.059 93th percentile
Risk Priority 97 floored blend · peak EPSS

Summary

CVE-2021-27101 is a critical-severity an unspecified weakness vulnerability in Accellion Fta. Its CVSS base score is 9.8 (Critical).

Operationally, ranked in the top 7% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

Accellion FTA versions 9_12_370 and earlier contain a SQL injection vulnerability triggered by a crafted Host header sent to the document_root.html endpoint. The affected component is the Accellion File Transfer Appliance (FTA), a managed file transfer product. The issue received a CVSS 3.1 score of 9.8, reflecting network-accessible attack vectors that require no authentication or user interaction.

An unauthenticated remote attacker can supply a malicious Host header to inject arbitrary SQL statements, resulting in full read, write, and delete access to the underlying database and potentially the host system. Successful exploitation grants complete control over confidentiality, integrity, and availability of data processed by the appliance.

Vendor guidance states that the flaw is resolved in FTA version 9_12_380 and later. The vulnerability appears in CISA's catalog of known exploited vulnerabilities, confirming observed in-the-wild use against unpatched deployments.

EU & UK References

Vulnerability Data

Accellion FTA 9_12_370 and earlier is affected by SQL injection via a crafted Host header in a request to document_root.html. The fixed version is FTA_9_12_380 and later.

CWE(s)
KEV Date Added
03 November 2021

Related Threats

CVEs Like This One

CVE-2021-27102Same product: Accellion Ftaboth on KEV
CVE-2021-27104Same product: Accellion Ftaboth on KEV
CVE-2021-27103Same product: Accellion Ftaboth on KEV
CVE-2025-53896Same product class: managed file transfer
CVE-2026-29092Same product class: managed file transfer
CVE-2026-24782Same product class: managed file transfer
CVE-2025-53897Same product class: managed file transfer
CVE-2026-24752Same product class: managed file transfer
CVE-2026-28271Same product class: managed file transfer
CVE-2026-28269Same product class: managed file transfer

Affected Assets

accellion
fta
≤ 9_12_370

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References