LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-27103: Accellion FTA Server-Side Request Forgery (SSRF) Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Nov 17, 2021
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-27103 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of Nov 17, 2021 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Accellion FTA contains a server-side request forgery (SSRF) vulnerability exploited via a crafted POST request to wmProgressstat.html.

CVE-2021-27103 is a server-side request forgery (SSRF) vulnerability in Accellion FTA. An attacker can abuse it with a crafted POST request to wmProgressstat.html, potentially allowing the server to make unintended requests. This matters because Accellion FTA is used for secure file transfer; successful exploitation can expose internal systems or data, and the vulnerability has been used in ransomware operations. Confirm all product and version details against the vendor advisory.

How it works

This flaw falls under CWE-918 (Server-Side Request Forgery). In an SSRF weakness, the application accepts attacker-controlled input that influences outbound requests made by the server itself. According to the CISA summary, the issue in Accellion FTA is triggered via a crafted POST request to the wmProgressstat.html endpoint. A technical reader should understand that the attacker does not need to reach internal hosts directly; instead they coerce the FTA server into initiating connections or requests on their behalf. Exact request parameters, response behavior, and any chaining with other flaws are not detailed in the provided facts and must be confirmed against the vendor advisory. Do not assume specific payloads or internal targets beyond the general SSRF class.

Am I affected? How to find it in your systems

Accellion FTA is typically deployed as an on-premises or appliance-based secure file-transfer solution, often facing the internet or partner networks to handle external file exchange. Inventory any hosts or virtual appliances running Accellion FTA software. Check management consoles, asset databases, and network scans for FTA-related services or hostnames. Because exact affected version ranges are not supplied here, compare your installed build against the vendor advisory before declaring a system safe or vulnerable.

Absence of obvious log hits does not prove non-exploitation; SSRF traffic can be low-volume and blend with legitimate activity.

How to remediate

Patch first. CISA’s required action is to apply updates per vendor instructions. Obtain the fixed release or security update directly from the Accellion (or successor) advisory for CVE-2021-27103 and install it on every FTA instance. After patching, verify the version string and re-test the previously vulnerable endpoint if the vendor provides a verification method.

Beyond the patch, harden the broader class of SSRF risks:

If you can't patch immediately

Implement compensating controls while you schedule the update:

These measures reduce but do not eliminate risk; treat them as temporary.

If your data may have been exposed

Actively exploited vulnerabilities, including those with known ransomware use, frequently lead to data theft or encryption. If you have evidence of exploitation or cannot rule it out, treat the incident as a potential breach: isolate affected systems, preserve logs, and follow your incident-response plan. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data sets to see whether credentials or personal information have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedAccellion · FTA
WeaknessCWE-918
Added to CISA KEVNov 3, 2021
Federal patch deadlineNov 17, 2021
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities