Cleo Releases Patches for Cleo MFT Zero-day Vulnerability
ID: 69d008fa-ec6b-5714-b704-41eb891aec89
STIX ID: report--69d008fa-ec6b-5714-b704-41eb891aec89
Feed Name: Arctic Wolf
Threat Score
Cleo released patches (fixed in version 5.8.0.24) for a zero-day RCE in Cleo Managed File Transfer products that allowed unauthenticated attackers to import and execute arbitrary shell commands via default Autorun directory behavior; Arctic Wolf observed active exploitation starting December 7, 2024, a PoC is public, and reporting links Termite ransomware actors to the campaign, with Arctic Wolf advising immediate patching or removal of internet-exposed systems as a workaround.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
