A critical CrushFTP zero-day, tracked as CVE-2025-54309, has been reported as actively exploited in the wild, prompting urgent warnings from security researchers and national incident responders. The flaw affects CrushFTP 11.x and 10.x builds including 11.3.4_23 and later and 10.8.5 and later, and can allow attackers to bypass authentication and obtain administrator access over HTTPS when the DMZ proxy service is disabled. The issue has been assigned a CVSS 3.1 score of 9.0 and has been linked to improper AS2 validation in vulnerable versions.
CrushFTP released fixes in 11.3.4_26 and 10.8.5_12, and defenders were urged to patch immediately or restore the application’s original configuration from clean backups created on or before July 16 if patching is not yet possible. Reported indicators of compromise include changes to MainUsers/default/user.xml containing the string last_logins, creation of unknown administrator accounts with long identifiers, unusual UI behavior, administrator logins from unfamiliar IP addresses, and altered permissions on sensitive directories.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
CrushFTP developers released updates to fix CVE-2025-54309, an authentication bypass vulnerability affecting certain 10.x and 11.x versions. The recommended fixed versions are 11.3.4_26 and 10.8.5_12.
Rapid7 and CSIRT.SK reported that CVE-2025-54309 was being actively exploited as a zero-day. The flaw can allow attackers to bypass authentication and gain administrator access over HTTPS when the DMZ proxy service is disabled.
CSIRT.SK advised administrators who could not patch immediately to restore CrushFTP's original configuration from clean backups created on or before July 16. The same guidance highlighted indicators of compromise such as altered user.xml entries, unknown administrator accounts, and suspicious admin logins.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.