EXPOSURES › CVE-2021-27102
CVE-2021-27102
CRITICAL ⌖ ON CISA KEV · EXPLOITEDAccellion FTA's OS command injection vulnerability was actively exploited, likely contributing to ransomware attacks and data breaches affecting numerous DIB organizations and FedRAMP vendors who used it as a component in their systems.
A critical OS command injection vulnerability in Accellion FTA allowed attackers to execute arbitrary commands, leading to data exfiltration and likely ransomware deployment. DIB organizations using FTA, or vendors incorporating it, face significant compliance risks (NIST 800-171) and potential legal repercussions; immediate remediation and thorough supply chain assessment are essential.
Shame score — The vulnerability's exploitation in ransomware attacks and widespread use within the DIB demonstrates a significant failure in secure development practices and risk management.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Accellion FTA contains an OS command injection vulnerability exploited via a local web service call.
"Accellion FTA contains an OS command injection vulnerability exploited via a local web service call."
| PRODUCT | STATUS |
|---|---|
| Kiteworks Federal Cloud Accellion USA, LLC. |
Authorized |