logo

CrushFTP Zero-Day Exploitation Due to CVE-2024-4040

ID: c4e21875-943a-5431-9671-5b8c29103eaa

STIX ID: report--c4e21875-943a-5431-9671-5b8c29103eaa

Feed Name: Qualys Blog

Threat Score
90/100

Date Published: 2024-04-30

Date Updated: 2026-04-28

Author: Sheela Sarva

...
...

CrushFTP disclosed a high-severity zero-day (CVE-2024-4040) affecting 9.x, versions prior to 10.7.1, and 11.1.0 that permits unauthenticated VFS sandbox escape and remote code execution; the flaw carries a CVSS of 9.8, has been observed exploited to read sensitive files, was added to CISA's KEV catalog, and Qualys released a detection QID with vendor-upgrade guidance to remediate.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.