Accellion develops secure file transfer and managed content delivery appliances, primarily through its Kiteworks and File Transfer Appliance product lines, which serve as trusted conduits for sensitive document exchange in regulated enterprises. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated tendency toward critical severity, and have a moderate tendency toward both confirmed in-the-wild exploitation and public exploit availability. The exposure concentrates in these gateway appliances and recurs through web-facing input-handling weakness classes including cross-site scripting, OS command injection, and SQL injection, alongside authorization-bypass flaws that allow attackers to circumvent access controls on file repositories. Given the appliances' role protecting high-value confidential data, these vulnerabilities present a material risk to data exfiltration; defenders should prioritize patching and network segmentation around these systems. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Accellion over time
Signals from CVEs in this vendor scope (65 CVEs).
65 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-27104CRITICAL Accellion FTA 9_12_370 and earlier is affected by OS command execution via a crafted POST request to various admin endpoints. The fixed version is FTA_9_12_380 and later. | Feb 16, 2021 | 9.8 | 89 | YES | NO |
CVE-2015-2857CRITICAL Accellion File Transfer Appliance before FTA_9_11_210 allows remote attackers to execute arbitrary code via shell metacharacters in the oauth_token parameter. | Aug 22, 2017 | 9.8 | 85 | NO | YES |
CVE-2021-27103CRITICAL Accellion FTA 9_12_411 and earlier is affected by SSRF via a crafted POST request to wmProgressstat.html. The fixed version is FTA_9_12_416 and later. | Feb 16, 2021 | 9.8 | 74 | YES | NO |
CVE-2021-27101CRITICAL Accellion FTA 9_12_370 and earlier is affected by SQL injection via a crafted Host header in a request to document_root.html. The fixed version is FTA_9_12_380 and later. | Feb 16, 2021 | 9.8 | 72 | YES | NO |
CVE-2021-27102HIGH Accellion FTA 9_12_411 and earlier is affected by OS command execution via a local web service call. The fixed version is FTA_9_12_416 and later. | Feb 16, 2021 | 7.8 | 64 | YES | NO |
CVE-2015-2856HIGH Directory traversal vulnerability in the template function in function.inc in Accellion File Transfer Appliance devices before FTA_9_11_210 allows remote attackers to read arbitrar | Oct 10, 2017 | 7.5 | 61 | NO | YES |
CVE-2021-31586HIGH Accellion Kiteworks before 7.4.0 allows an authenticated user to perform SQL Injection via LDAPGroup Search. | Jun 23, 2021 | 8.8 | 48 | NO | NO |
CVE-2017-8303CRITICAL An issue was discovered on Accellion FTA devices before FTA_9_12_180. seos/1000/find.api allows Remote Code Execution with shell metacharacters in the method parameter. | May 5, 2017 | 9.8 | 42 | NO | NO |
CVE-2026-24782HIGH Kiteworks is a private data network (PDN). Prior to version 9.3.0,ultiple SQL Injection vulnerabilities in Kiteworks Secure Data Forms could be exploited by an authenticated attack | Jun 1, 2026 | 8.8 | 35 | NO | NO |
CVE-2026-24751HIGH Kiteworks is a private data network (PDN). Prior to version 9.3.0, a reflected XSS vulnerability in Kiteworks Secure Data Forms could allow an external attacker to trick a user int | Jun 1, 2026 | 8.2 | 35 | NO | NO |
Signals from CVEs in this vendor scope (65 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Accellion.
Media articles that mention a CVE ID that affects a product developed by Accellion — matched by CVE ID, not by vendor name.