Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Accellion

First CVE: Aug 27, 2008Active for: 18 yearsTotal CVEs: 65
58.6
VTI Score
TOP TARGET

Accellion develops secure file transfer and managed content delivery appliances, primarily through its Kiteworks and File Transfer Appliance product lines, which serve as trusted conduits for sensitive document exchange in regulated enterprises. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated tendency toward critical severity, and have a moderate tendency toward both confirmed in-the-wild exploitation and public exploit availability. The exposure concentrates in these gateway appliances and recurs through web-facing input-handling weakness classes including cross-site scripting, OS command injection, and SQL injection, alongside authorization-bypass flaws that allow attackers to circumvent access controls on file repositories. Given the appliances' role protecting high-value confidential data, these vulnerabilities present a material risk to data exfiltration; defenders should prioritize patching and network segmentation around these systems. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
65
Total CVEs
More Total CVEs than 99% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
7.4
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
6.2%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Accellion over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 27, 2008
17 years ago
Most Recent CVE
Jun 1, 2026
53 days ago

Products(8 total)

Top CVEs

Signals from CVEs in this vendor scope (65 CVEs).

65 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-27104CRITICAL
Accellion FTA 9_12_370 and earlier is affected by OS command execution via a crafted POST request to various admin endpoints. The fixed version is FTA_9_12_380 and later.
Feb 16, 20219.889YESNO
CVE-2015-2857CRITICAL
Accellion File Transfer Appliance before FTA_9_11_210 allows remote attackers to execute arbitrary code via shell metacharacters in the oauth_token parameter.
Aug 22, 20179.885NOYES
CVE-2021-27103CRITICAL
Accellion FTA 9_12_411 and earlier is affected by SSRF via a crafted POST request to wmProgressstat.html. The fixed version is FTA_9_12_416 and later.
Feb 16, 20219.874YESNO
CVE-2021-27101CRITICAL
Accellion FTA 9_12_370 and earlier is affected by SQL injection via a crafted Host header in a request to document_root.html. The fixed version is FTA_9_12_380 and later.
Feb 16, 20219.872YESNO
CVE-2021-27102HIGH
Accellion FTA 9_12_411 and earlier is affected by OS command execution via a local web service call. The fixed version is FTA_9_12_416 and later.
Feb 16, 20217.864YESNO
CVE-2015-2856HIGH
Directory traversal vulnerability in the template function in function.inc in Accellion File Transfer Appliance devices before FTA_9_11_210 allows remote attackers to read arbitrar
Oct 10, 20177.561NOYES
CVE-2021-31586HIGH
Accellion Kiteworks before 7.4.0 allows an authenticated user to perform SQL Injection via LDAPGroup Search.
Jun 23, 20218.848NONO
CVE-2017-8303CRITICAL
An issue was discovered on Accellion FTA devices before FTA_9_12_180. seos/1000/find.api allows Remote Code Execution with shell metacharacters in the method parameter.
May 5, 20179.842NONO
CVE-2026-24782HIGH
Kiteworks is a private data network (PDN). Prior to version 9.3.0,ultiple SQL Injection vulnerabilities in Kiteworks Secure Data Forms could be exploited by an authenticated attack
Jun 1, 20268.835NONO
CVE-2026-24751HIGH
Kiteworks is a private data network (PDN). Prior to version 9.3.0, a reflected XSS vulnerability in Kiteworks Secure Data Forms could allow an external attacker to trick a user int
Jun 1, 20268.235NONO
View all 65 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products65 CVEs
45%
35%
20%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local4 (6.2%)
Network54 (83.1%)
Unknown7 (10.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low56 (86.2%)
High2 (3.1%)
Unknown7 (10.8%)
User Interaction
None41 (63.1%)
Unknown7 (10.8%)
Required17 (26.2%)
Privileges Required
Low20 (30.8%)
High6 (9.2%)
None32 (49.2%)
Unknown7 (10.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (65 CVEs).

CISA KEV
4 CVEs
6.2% of CVEs· 100th percentile
Metasploit
2 CVEs
3.1% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
5 CVEs
7.7% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Accellion.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Accellion — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Accellion's Products

View all 4 CNAs →

Top CWEs