CrushFTP warned customers to patch an actively exploited zero-day, now tracked as CVE-2024-4040, that lets unauthenticated attackers escape the product’s virtual file system sandbox and download system files. The company said the flaw was reported and patched immediately, with fixes released in CrushFTP v10.7.1 and v11.1.0; organizations still running v9 were urged to upgrade to v11 or apply updates through the product dashboard. Airbus CERT also published a public scanner for the vulnerability on GitHub, underscoring rapid defender and researcher interest in identifying exposed systems.
CrowdStrike said the bug was exploited in the wild in targeted attacks against multiple U.S. organizations and assessed the activity as an intelligence-gathering campaign that was likely politically motivated. CrushFTP added that deployments using a DMZ in front of the main instance were protected from the observed attacks, while internet exposure remained a major concern: Shodan data cited in reporting showed roughly 2,700 CrushFTP instances with their web interface accessible online, expanding the pool of potentially vulnerable targets.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Airbus CERT published a GitHub repository for a scanner related to CVE-2024-4040. This made a dedicated detection tool publicly available for the CrushFTP vulnerability.
CrushFTP warned customers about an actively exploited zero-day vulnerability that allows unauthenticated attackers to escape the virtual file system sandbox and download system files. CrowdStrike confirmed in-the-wild exploitation in targeted attacks against multiple U.S. organizations and assessed the activity as likely politically motivated intelligence gathering.
CrushFTP said the vulnerability later tracked as CVE-2024-4040 was reported on April 19, 2024, and patched immediately. The fix was released in CrushFTP versions 10.7.1 and 11.1.0, while v9 users were urged to upgrade or update via the dashboard.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.