logo

New Cleo zero-day RCE flaw exploited in data theft attacks

ID: fe93c93b-ed85-5eb4-b31c-35a107c52950

STIX ID: report--fe93c93b-ed85-5eb4-b31c-35a107c52950

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2024-12-10

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

A zero-day bypass affecting Cleo managed file transfer products (LexiCom, VLTrader, Harmony) is being actively exploited to upload malicious files into autorun directories, execute PowerShell commands that fetch JAR payloads and deploy webshells, and exfiltrate data; evidence links activity to IPs across multiple countries and to the Termite ransomware group, and defenders are advised to restrict internet exposure, search for specific TXT/XML artifacts and JAR files, disable autorun, and apply forthcoming patches.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.