Rapid7 Critical RCE Vulnerability in WS_FTP Server Disclosed
Article Content
- •CVE-2023-40044 allows unauthenticated remote code execution in WS_FTP Server.
- •The vulnerability affects versions prior to 8.7.4 and 8.8.2 of the software.
- •Rapid7 suggests a CVSS score of 9.8, indicating high severity and exploitability.
On September 27, 2023, Progress Software disclosed CVE-2023-40044, a .NET deserialization vulnerability in the Ad Hoc Transfer module of WS_FTP Server. This flaw allows unauthenticated attackers to execute remote commands on affected systems. The vulnerability is present in versions prior to 8.7.4 and 8.8.2. Rapid7's analysis indicates that the vulnerability is trivially exploitable, with a suggested CVSS score of 9.8, contrasting with NIST's score of 8.8 due to differing interpretations of privilege requirements. The vulnerability was first publicly demonstrated with a proof of concept on October 2, 2023, and was added to CISA's Known Exploited Vulnerabilities Catalog on October 5, 2023. Organizations using affected versions are at significant risk, and immediate action is recommended to mitigate potential exploitation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Progress Software and CVE-2023-40044 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…