logo

Qualys Hacked Using Accellion Zero-day Vulnerability

ID: 871cf91e-06b6-593f-b924-0262543565c1

STIX ID: report--871cf91e-06b6-593f-b924-0262543565c1

Feed Name: Cyble Blog

Threat Score
85/100

Date Published: 2024-11-08

Date Updated: 2026-07-20

...
...

The report documents Clop ransomware's exploitation of Accellion FTA (including a disclosed zero-day and subsequent CVEs) to deploy web shells, exfiltrate sensitive files from multiple organizations, and publish stolen data on a darkweb leak site; it includes technical details (CVE-2021-27101/27102/27103/27104, web-shell file paths), observed victim incidents (Qualys, ExecuPharm, V Cargo, Bombardier, Fugro), and mitigation recommendations such as patching to FTA_9_12_432+, auditing accounts, and increasing access controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.