CVE-2021-27104
Accellion FTA OS Command Injection Vulnerability
Accellion FTA 9_12_370 and earlier is affected by OS command execution via a crafted POST request to various admin endpoints. The fixed version is FTA_9_12_380 and later.
CRITICAL · CVSS 9.8
⚠ CISA KEV
EPSS 0.06393
Ransomware: known
Act now
- Listed on CISA KEV (known exploited in the wild)
- Linked to known ransomware campaigns
- SSVC exploitation status: active
- EPSS percentile: top 9% of all CVEs by exploitation likelihood
- CVSS base score ≥ 7.0
Sigma rules10
YARA rules0