CVE-2021-27101
Accellion FTA SQL Injection Vulnerability
Accellion FTA 9_12_370 and earlier is affected by SQL injection via a crafted Host header in a request to document_root.html. The fixed version is FTA_9_12_380 and later.
CRITICAL · CVSS 9.8
⚠ CISA KEV
EPSS 0.00813
Ransomware: known
Act now
- Listed on CISA KEV (known exploited in the wild)
- Linked to known ransomware campaigns
- SSVC exploitation status: active
- CVSS base score ≥ 7.0
Sigma rules10
YARA rules0