logo

Patch Now: CrushFTP Zero-Day Cloud Exploit Targets US Orgs

ID: 5a11c51d-13e7-5f65-bff4-3db31ab6de2b

STIX ID: report--5a11c51d-13e7-5f65-bff4-3db31ab6de2b

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-04-24

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

CrushFTP disclosed and patched CVE-2024-4040 — an improper input validation flaw in version 11.1 that allows unauthenticated escape from the virtual file system and arbitrary file access; researchers (Rapid7) believe it can be leveraged as a server-side template injection enabling admin bypass and full RCE. Proof-of-concept exploit code and scanning scripts were published, active targeted exploitation against U.S. organizations has been observed, and tens of thousands of servers are discoverable online; organizations are advised to upgrade to the patched release immediately and implement additional hardening (Limited Server mode, firewalls, DMZ restrictions).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.