logo

CVE-2024-4040 exploited in the wild: everything you need to know

ID: 7b47de2b-5abc-5f10-8415-07e75f8f3081

STIX ID: report--7b47de2b-5abc-5f10-8415-07e75f8f3081

Feed Name: Wiz Blog

Threat Score
90/100

Date Published: 2024-04-24

Date Updated: 2026-05-01

...
...

On April 19, 2024 CrushFTP disclosed CVE-2024-4040, a critical VFS sandbox escape affecting versions prior to 10.7.1 and 11.1.0; researchers escalated the severity after demonstrating unauthenticated remote code execution and observed exploitation in the wild. The flaw (CVSS 9.8) is exploitable via the web interface only, affects a subset of cloud deployments (Wiz reports ~1.7% vulnerable, ~0.4% internet-exposed), and organizations are advised to upgrade to 10.7.1 or 11.1.0 immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.