logo

Cleo Releases Patches for Cleo MFT Zero-day Vulnerability

ID: fb70df86-d040-570f-b488-ebf62c554d3a

STIX ID: report--fb70df86-d040-570f-b488-ebf62c554d3a

Feed Name: Arctic Wolf Blog

Threat Score
85/100

Date Published: 2024-12-12

Date Updated: 2026-04-27

...
...

On December 11, 2024 Cleo released patches (fixed in 5.8.0.24) for a zero-day RCE in Cleo Managed File Transfer products (Harmony, VLTrader, Lexicom) that allowed unauthenticated attackers to import and execute arbitrary shell commands via default Autorun directory settings. Arctic Wolf observed a mass-exploitation campaign beginning December 7, 2024, PoC code is public, and reporting links the vulnerability to actors deploying Termite ransomware; organizations are advised to patch immediately or remove internet-exposed Cleo systems until patched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.