CVE-2021-27102
Accellion FTA
Accellion FTA 9_12_411 and earlier is affected by OS command execution via a local web service call. The fixed version is FTA_9_12_416 and later.
- CVSS
- 7.8
- EPSS
- 3.62% 88.4% percentile
- CISA KEV
- Listed
- Published
- 2021.02.17
Accellion FTA 9_12_411 and earlier is affected by OS command execution via a local web service call. The fixed version is FTA_9_12_416 and later.
CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.
Accellion FTA 9_12_411 and earlier is affected by OS command execution via a local web service call. The fixed version is FTA_9_12_416 and later.
Confirm exposure before applying a vendor-supported change.
Apply updates per vendor instructions.
Due date: 2021.11.17Confirm that Accellion FTA and an affected version are present.
Combine exploitation signals with asset exposure and business criticality.
Follow the vendor advisory or supported update path and preserve rollback options.
Recheck the version, service health, access paths, and relevant logs.