logo

Over 12,000 KerioControl firewalls exposed to exploited RCE flaw

ID: 5e0a9451-551b-5667-b615-8a9ba2e4f35d

STIX ID: report--5e0a9451-551b-5667-b615-8a9ba2e4f35d

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2025-02-10

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A critical RCE in GFI KerioControl (CVE-2024-52875) with a public PoC is being actively exploited to steal admin CSRF tokens and enable 1‑click remote code execution; tens of thousands of instances remain unpatched and administrators are advised to install KerioControl 9.4.5 Patch 2 immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.