logo

Censys Warns 6 Million Public FTP Servers Remain Exposed Online in 2026

ID: 8ebd9820-f3ac-5be6-be21-96be4d8f4932

STIX ID: report--8ebd9820-f3ac-5be6-be21-96be4d8f4932

Feed Name: Cyber Press

Threat Score
55/100

Date Published: 2026-04-17

Date Updated: 2026-04-17

Author: AnuPriya

...
...

#### Executive summary A Censys security brief finds roughly 5.94 million internet-facing FTP servers remain exposed in 2026—concentrated in shared hosting and residential networks—with about 2.45 million lacking TLS and many instances resulting from insecure defaults (e.g., Pure-FTPd cPanel defaults, misconfigured IIS, and legacy/backdoored vsftpd 2.3.4). The report urges disabling FTP where unnecessary, migrating to SFTP, validating TLS configurations, and auditing internet-facing assets to reduce this substantial attack surface.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.