Skip to content
Exploitation of CVE-2024-4040 and CVE-2025-8875 in CrushFTP and RXERIUM

Exploitation of CVE-2024-4040 and CVE-2025-8875 in CrushFTP and RXERIUM

First seen 26 Sep 2026, 10:21 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 27, 2026 at 16:34 UTC
  • •CVE-2024-4040 is actively exploited, allowing unauthorized file access in CrushFTP.
  • •CVE-2025-8875 affects systems running version 2025.3.1.9 or older, with confirmed exploitation.
  • •Security professionals should utilize available PoCs and templates to assess vulnerabilities.

Recent cybersecurity reports highlight two significant vulnerabilities: CVE-2024-4040 and CVE-2025-8875. CVE-2024-4040, related to a bypass vulnerability in CrushFTP, was published on April 22, 2024, and has been actively exploited since April 24, 2024. A proof-of-concept (PoC) script is available that attempts to read files outside the sandbox, indicating a serious risk for affected systems. Meanwhile, CVE-2025-8875, disclosed on August 14, 2025, affects systems running version 2025.3.1.9 or older, with active exploitation confirmed as of August 13, 2025. Security professionals are urged to implement the provided templates and scripts to assess their systems for these vulnerabilities. Both vulnerabilities pose a significant risk to organizations using the affected software.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2024-04-22
CVE-2024-4040 published
A bypass vulnerability in CrushFTP was disclosed, allowing potential unauthorized access.
Sploitus
2024-04-23
First public PoC for CVE-2024-4040
A proof-of-concept script was released, demonstrating the exploit's capabilities.
Sploitus
2024-04-24
CVE-2024-4040 added to CISA KEV
CISA confirmed active exploitation of CVE-2024-4040 shortly after its publication.
Sploitus
2025-08-13
CVE-2025-8875 added to CISA KEV
CISA confirmed active exploitation of CVE-2025-8875 on the day prior to its public disclosure.
Sploitus
2025-08-14
CVE-2025-8875 published
A vulnerability affecting versions 2025.3.1.9 and older was disclosed, posing a risk to users.
Sploitus
2025-08-18
First public PoC for CVE-2025-8875
A proof-of-concept for CVE-2025-8875 was made publicly available, demonstrating the vulnerability.
Sploitus

More articles in this cluster (2)

Following this threat?

Track CVE-2024-4040 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed