CVE-2024-4040Active Exploitation(crushftp / crushftp)

LOWCVSS 10.0 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for crushftp crushftp systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.

3.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-05-01. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-1336CWE-94

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • crushftp

Threat summary

  • Active exploitation appears in 1 classified signals
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
crushftp

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-03: 1Active Exploitation · 2026-03-03: 1Technical Details · 2026-03-03: 103-03
Signal classification1 categories
Active Exploitation
1100.0%
Full discourse1 post
  • Anonymous Tech@Anonymous_Tech7
    Active Exploitation

    CrushFTP servers worldwide are under attack. Exploiting CVE-2024-4040 and CVE-2025-31161, attackers bypass authentication and achieve remote code execution, gaining control of the crushadmin account on vulnerable instances.

    Post summary

    Attackers are actively exploiting CVE‑2024‑4040 and CVE‑2025‑31161 on CrushFTP servers worldwide to bypass authentication, achieve remote code execution, and seize control of the crushadmin account.

    00010125
    1 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcrushftpcrushftp---

Explore more