logo

A Vulnerability in Multiple Cleo Products Could Allow for Remote Code Execution

ID: c6dd3320-55e0-5154-a034-90848e4da857

STIX ID: report--c6dd3320-55e0-5154-a034-90848e4da857

Feed Name: CISecurity.org Advisories

Threat Score
80/100

Date Published: 2024-12-12

Date Updated: 2026-04-27

...
...

A critical remote code execution vulnerability (CVE-2024-50623) affecting Cleo’s LexiCom, VLTransfer, and Harmony file-transfer products has been disclosed; it enables unrestricted file upload/download and is actively exploited in the wild. The advisory notes that systems — including those running version 5.8.0.21 — may still be exploitable despite existing patches and recommends moving internet-exposed Cleo systems behind a firewall until a new patch is released.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.