Accellion vendor intelligence
Accellion Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting Accellion products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 4
- Known exploited vulnerabilities affecting Accellion products
- In CISA KEV
- 4
- Records also listed in the official catalog
- Beyond CISA KEV
- 0
- Additional exploited CVEs absent from CISA KEV
- Sensor Observed
- 0
- Accellion KEVs with sensor-observed exploitation activity
The catalog gap matters for Accellion exposure
All four exploited Accellion CVEs tracked here are also listed in CISA KEV. Use product ownership and sensor evidence to prioritize within this portfolio.
- 100%
- Covered by CISA
- 0%
- Beyond CISA
- 1
- Product families
Attested Accellion CVEs
Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2021-27103
Accellion FTA 9_12_411 and earlier is affected by SSRF via a crafted POST request to wmProgressstat.html. The fixed version is FTA_9_12_416 and later. |
FTA | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-27101
Accellion FTA 9_12_370 and earlier is affected by SQL injection via a crafted Host header in a request to document_root.html. The fixed version is... |
FTA | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-27102
Accellion FTA 9_12_411 and earlier is affected by OS command execution via a local web service call. The fixed version is FTA_9_12_416 and later. |
FTA | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-27104
Accellion FTA 9_12_370 and earlier is affected by OS command execution via a crafted POST request to various admin endpoints. The fixed version is... |
FTA | Confirmed | In CISA | 03 Nov 2021 |
No Accellion CVEs match this search or filter.
Showing 4 of 4 Accellion known exploited vulnerabilities.
Recurring weakness patterns
Neutralization and server-side request forgery (ssrf) account for three mapped occurrences across this Accellion KEV portfolio.
Early warning alerts
Get alerts on high-impact exploitation
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.