New CrushFTP 0-Day Vulnerability Exploited in the Wild to Gain Access to Servers

Threat Score
71%
4 articles 100.0% Similarity 17 hours ago

Activity Timeline

CVE-2025-54309: CrushFTP Zero-Day Vulnerability Ex...
Tenable Cyber Exposure Alerts
Jul 18
20:46
CrushFTP zero-day exploited in attacks to gain adm...
BleepingComputer
Jul 18
22:24
New CrushFTP zero-day exploited in attacks to hija...
BleepingComputer
Jul 18
22:24
New CrushFTP 0-Day Vulnerability Exploited in the ...
Cybersecurity News
Primary Article
Jul 19
09:54
A critical zero-day flaw in the CrushFTP managed file-transfer platform was confirmed after vendor and threat-intelligence sources confirmed active exploitation beginning on 18 July 2025 at 09:00 CST. Tracked as CVE-2025-54309, the bug allows unauthenticated attackers to obtain full administrative control of vulnerable servers over HTTPS. CrushFTP says the issue was inadvertently resolved in builds […]...

Cluster AI

Beta Organization

Save to Folder

Choose a folder to save this cluster: