logo

Cleo Software Actively Being Exploited in the Wild CVE-2024-55956 | Huntress

ID: 825f9e71-bce6-57b6-8a4e-7b2b53a5bd18

STIX ID: report--825f9e71-bce6-57b6-8a4e-7b2b53a5bd18

Feed Name: Huntress Blog

Threat Score
80/100

Date Published: 2024-12-09

Date Updated: 2026-04-28

...
...

Huntress warns of active exploitation against Cleo LexiCom, VLTrader, and Harmony (<= 5.8.0.21) via an arbitrary file-write vulnerability that allows autorun processing to execute encoded PowerShell and fetch JAR-based webshells for persistence; the vendor patch 5.8.0.21 was shown to be insufficient, multiple victims were observed, and Huntress published IOCs and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.