logo

Critical Update: CrushFTP Zero-Day Flaw Exploited in Targeted Attacks

ID: 4d776099-6806-5623-80d5-e9ae7bc4f2c9

STIX ID: report--4d776099-6806-5623-80d5-e9ae7bc4f2c9

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2024-04-20

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

CrushFTP versions prior to v11.1 contain a critical server-side template injection (CVE-2024-4040, CVSS 9.8) that enables unauthenticated file reads and remote code execution; the flaw has been patched but was exploited in the wild in targeted attacks against U.S. entities, with Airbus CERT publishing scanners/IoC checks, Rapid7 confirming trivial exploitability, CrowdStrike reporting active use, and CISA adding it to the KEV catalog.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.