logo

Over 1,400 CrushFTP servers vulnerable to actively exploited bug

ID: 019a9727-dc45-55dd-a637-7866770224ab

STIX ID: report--019a9727-dc45-55dd-a637-7866770224ab

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2024-04-25

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

A critical CrushFTP zero-day (CVE-2024-4040) enabling unauthenticated arbitrary file read, admin-auth bypass, and remote code execution is being actively exploited in targeted attacks; researchers and vendors (Rapid7, CrowdStrike) confirmed exploitation, Shadowserver identified 1,401 unpatched public instances (Shodan shows 5,232 exposed servers), and CISA added the flaw to its Known Exploited Vulnerabilities list—customers are urged to apply vendor patches immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.