CrushFTP CVE-2024-4040: Crushed Expectations
ID: 3565c68c-7353-5cb6-ad32-3e3ae360aba5
STIX ID: report--3565c68c-7353-5cb6-ad32-3e3ae360aba5
Feed Name: Censys Blog
Date Published: 2024-04-24
Date Updated: 2026-04-27
Author: Ivonne Francia; The Censys Research Team
**CrushFTP CVE-2024-4040 (zero-day VFS escape) -- active exploitation observed and widespread exposure:** On April 19, 2024 CrushFTP patched a critical zero-day virtual file system escape in its WebInterface (CVE-2024-4040) that can allow unauthenticated access to system files and potential full system compromise; Censys observed ~4,899 hosts (5,704 instances) exposed on the internet and CrowdStrike reported exploitation attempts, vendor advisories contained confusing guidance, and Censys recommends immediate upgrade to patched versions (10.7.1 / 11.1.0).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
