logo

CrushFTP CVE-2024-4040: Crushed Expectations

ID: 3565c68c-7353-5cb6-ad32-3e3ae360aba5

STIX ID: report--3565c68c-7353-5cb6-ad32-3e3ae360aba5

Feed Name: Censys Blog

Threat Score
85/100

Date Published: 2024-04-24

Date Updated: 2026-04-27

Author: Ivonne Francia; The Censys Research Team

...
...

**CrushFTP CVE-2024-4040 (zero-day VFS escape) -- active exploitation observed and widespread exposure:** On April 19, 2024 CrushFTP patched a critical zero-day virtual file system escape in its WebInterface (CVE-2024-4040) that can allow unauthenticated access to system files and potential full system compromise; Censys observed ~4,899 hosts (5,704 instances) exposed on the internet and CrowdStrike reported exploitation attempts, vendor advisories contained confusing guidance, and Censys recommends immediate upgrade to patched versions (10.7.1 / 11.1.0).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.