← Vulnerability feed

Vulnerability record · CVE-2021-27101 · published 16 February 2021

CVE-2021-27101: Accellion FTA SQL injection via crafted Host header

Accellion · Fta

Accellion FTA 9_12_370 and earlier is affected by SQL injection through a crafted Host header in a request to document_root.html. The flaw is remotely reachable without authentication and carries a critical CVSS score, making it a serious risk for internet-facing FTA deployments.

9.8 CVSS 3.1 Critical CISA KEV since 3 Nov 2021 Known ransomware use EPSS 6.0% · top 6.9%
9.8CVSS 3.1 base score, v2 7.5
6.0%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References
17 Jun 2026Last modified by NVD

Description

Accellion FTA 9_12_370 and earlier is affected by SQL injection via a crafted Host header in a request to document_root.html. The fixed version is FTA_9_12_380 and later.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or user interaction, plus CISA KEV listing and documented ransomware campaign use, make this a top-priority patch.

What it is

Accellion FTA 9_12_370 and earlier is affected by SQL injection through a crafted Host header in a request to document_root.html. The flaw is remotely reachable without authentication and carries a critical CVSS score, making it a serious risk for internet-facing FTA deployments.

Impact

An attacker can inject SQL through the Host header, potentially reading or modifying backend data and, given the critical integrity and availability ratings, disrupting the application. The record does not detail the exact database contents exposed.

Attack surface

Reached over the network via an HTTP request to document_root.html with a crafted Host header. The CVSS vector shows no privileges required and no user interaction, so it is unauthenticated and remotely triggerable.

Exploitation

Listed in CISA KEV with known ransomware campaign use, and EPSS 30-day probability is about 6 percent (92.9th percentile). Reference tags are vendor advisory, third-party advisory and US government resource; no public exploit code tag is present.

What to do

  • Upgrade FTA to 9_12_380 or later, the fixed version named in the record.
  • If immediate upgrade is not possible, restrict network access to FTA management and document_root endpoints to trusted sources.
  • Validate and normalize the Host header at the reverse proxy or web server before it reaches FTA.
  • Monitor vendor and CISA KEV guidance for this CVE and apply the required action.
  • Treat any FTA host as potentially compromised and review it for signs of intrusion.

Detection

  • Search web and proxy logs for requests to document_root.html with unusual or malformed Host header values.
  • Look for SQL metacharacters or injection patterns in Host header fields in HTTP request logs.
  • Alert on unexpected outbound connections or file activity from FTA servers consistent with post-exploitation.
  • Correlate FTA access logs with authentication and process events around the same timeframe.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-27101 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Accellion FTA SQL Injection Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-27101 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2021-27101), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.