LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-27101: Accellion FTA SQL Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Nov 17, 2021
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-27101 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of Nov 17, 2021 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Accellion FTA contains a SQL injection vulnerability exploited via a crafted host header in a request to document_root.html.

CVE-2021-27101 is a SQL injection vulnerability in Accellion FTA. Attackers can abuse it by sending a crafted Host header in a request to document_root.html, which can let them interfere with backend database queries. This matters because Accellion FTA is used to move and share files; successful abuse can expose sensitive data and has been tied to ransomware activity. Confirm all product and fix details against the vendor advisory.

How it works

The flaw falls under CWE-89 (SQL injection) and CWE-138 (improper neutralization of special elements). In simple terms, the application does not adequately separate untrusted input from SQL statements. An attacker supplies a malicious Host header when requesting document_root.html. If that value is incorporated into a database query without proper validation or parameterization, the attacker can alter the query’s meaning.

At a technical level this can allow unauthorized reads, writes, or other database operations depending on the privileges of the application’s database account. Exact query structure, injectable parameters, and resulting impact are not detailed in the public summary; treat any deeper exploit mechanics as unconfirmed until verified against the vendor advisory and your own testing in a controlled environment. Do not assume blind or time-based techniques, stacked queries, or specific payloads without evidence from your logs or the advisory.

Am I affected? How to find it in your systems

Accellion FTA is typically deployed as an on-premises or managed file-transfer appliance or server used by enterprises to exchange large or sensitive files with partners and internal users. Inventory any hosts, virtual machines, or appliances running Accellion FTA, including older or forgotten instances in DMZs, partner zones, or backup environments.

How to remediate

Patch first. Apply the updates provided by the vendor exactly as described in their advisory and in line with CISA’s required action: “Apply updates per vendor instructions.” Schedule the upgrade in a maintenance window, take a verified backup, and validate that the FTA service and dependent workflows still function after the update.

After patching, harden the installation for this class of weakness:

If you can't patch immediately

Reduce exposure until the vendor update can be applied:

These steps only buy time; they do not replace the vendor patch.

If your data may have been exposed

This vulnerability has been exploited in the wild and is associated with ransomware operations. If your Accellion FTA instance was unpatched and reachable, treat it as a potential breach: isolate the system, preserve logs and disk images, and begin incident-response procedures including credential rotation and review of files that transited the appliance. Determine whether sensitive data left the environment and notify stakeholders according to your policies and legal requirements. You can also run a free exposure scan of your email addresses against known breach data sets to see whether associated credentials or personal information have appeared in prior incidents, then force password resets and enable multi-factor authentication where needed.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedAccellion · FTA
WeaknessCWE-89
Added to CISA KEVNov 3, 2021
Federal patch deadlineNov 17, 2021
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities