logo

Cleo Releases Patches for Cleo MFT Zero-day Vulnerability

ID: b249989f-2e1a-5664-9458-a0715f2d0702

STIX ID: report--b249989f-2e1a-5664-9458-a0715f2d0702

Feed Name: Arctic Wolf

Threat Score
85/100

Date Published: 2024-12-12

Date Updated: 2026-07-25

Author: Andres Ramos

...
...

Arctic Wolf reported a zero-day remote code execution vulnerability in Cleo Managed File Transfer (MFT) products that allowed unauthenticated attackers to import and run arbitrary shell commands by abusing default Autorun directory settings; active exploitation was observed starting 7 December 2024, a proof-of-concept is available, and reports indicate possible use by Termite ransomware. Cleo released fixes in version 5.8.0.24 for Harmony, VLTrader, and Lexicom and recommends immediate patching or removing internet-exposed systems as a temporary mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.