CRITICAL
CVE-2021-27104
CVSS
9.8
KEV
Description
Accellion FTA 9_12_370 and earlier is affected by OS command execution via a crafted POST request to various admin endpoints. The fixed version is FTA_9_12_380 and later.
Summary dbcve.org
OS command injection vulnerability in Accellion FTA versions 9_12_370 and earlier allowing remote attackers to execute arbitrary operating system commands via crafted POST requests to admin endpoints.
Mitigation
Upgrade to FTA_9_12_380 or later; if immediate patching is not feasible, restrict network access to admin interfaces to trusted networks only and implement monitoring for indicators of compromise.
Weakness (CWE)
CWE-78
OS Command Injection
EPSS Score
56.69%
Probability of exploitation in next 30 days
99th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.