Skip to content
COOEY

EXPOSURES › CVE-2021-27104

CVE-2021-27104

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-27104 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 ransomwarerceexploited-in-wildunpatched

Accellion FTA's OS command injection vulnerability allowed attackers to execute arbitrary commands, leading to data exfiltration and ransomware attacks.

A command injection vulnerability in Accellion FTA allowed attackers to execute arbitrary OS commands via crafted POST requests, resulting in data breaches and ransomware infections. DIB organizations using FTA face significant compliance risks (NIST 800-171) and potential data exposure; immediate patching and security posture review are critical.

Shame score — The vulnerability was actively exploited in ransomware attacks, indicating a severe lack of security controls and a significant operational impact.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Accellion FTA contains an OS command injection vulnerability exploited via a crafted POST request to various admin endpoints.

SENTIMENT · TRUSTED SOURCES
synthesis neutral +0.00
No sentiment expressed; sources are technical databases or generic pages without commentary on Accellion's handling.
cooey ↗ neutral +0.00
Neutral; technical description only.
"Accellion FTA contains an OS command injection vulnerability exploited via a crafted POST request to various admin endpoints."
NVD ↗ neutral +0.00
Neutral; unrelated CVE page.
"NVD - CVE-2026-56164"
CISA ↗ neutral +0.00
Neutral; generic CISA page.
"CISA Adds Four Known Exploited Vulnerabilities to Catalog"
SentinelOne ↗ neutral +0.00
Neutral; unrelated SentinelOne page.
"Vulnerability Database | SentinelOne"
www.cvefind.com ↗ neutral +0.00
Neutral; generic CVE database.
"CVE, short for Common Vulnerabilities and Exposures, is a list of publicly disclosed computer security flaws."
cvefeed.io ↗ neutral +0.00
Neutral; generic KEV catalog.
"CISA's Known Exploited Vulnerabilities (KEV) catalog is the authoritative list of security flaws that have been confirmed exploited in real-world attacks."
AFFECTED FEDRAMP PRODUCTS · 1
PRODUCTSTATUS
Kiteworks Federal Cloud
Accellion USA, LLC.
Authorized