Patch Now: CrushFTP Zero-Day Cloud Exploit Targets US Orgs
ID: 5a11c51d-13e7-5f65-bff4-3db31ab6de2b
STIX ID: report--5a11c51d-13e7-5f65-bff4-3db31ab6de2b
Feed Name: Dark Reading
Date Published: 2024-04-24
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
CrushFTP disclosed and patched CVE-2024-4040 — an improper input validation flaw in version 11.1 that allows unauthenticated escape from the virtual file system and arbitrary file access; researchers (Rapid7) believe it can be leveraged as a server-side template injection enabling admin bypass and full RCE. Proof-of-concept exploit code and scanning scripts were published, active targeted exploitation against U.S. organizations has been observed, and tens of thousands of servers are discoverable online; organizations are advised to upgrade to the patched release immediately and implement additional hardening (Limited Server mode, firewalls, DMZ restrictions).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
