logo

New CrushFTP zero-day exploited in attacks to hijack servers

ID: 8a3e2da6-0e12-50ef-911a-b22035790c9d

STIX ID: report--8a3e2da6-0e12-50ef-911a-b22035790c9d

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2025-07-18

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

CrushFTP warns of an actively exploited zero-day (CVE-2025-54309) that grants administrative access via the web interface on versions prior to v10.8.5 and v11.3.4_23; exploitation was first observed around July 18. IOCs include unexpected modifications to MainUsers/default/user.XML and creation of unrecognized admin-level usernames; administrators are advised to restore pre-July 16 backups if compromised, apply available patches, review logs, and harden access (IP whitelisting, DMZ caution, automatic updates).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.