Attackers are actively exploiting critical vulnerabilities in Cleo Harmony, Cleo VLTrader, and Cleo LexiCom managed file transfer software, including CVE-2024-50623 and the related CVE-2024-55956. The flaws affect versions prior to 5.8.0.24 and allow remote, unauthenticated attackers to upload arbitrary files, execute commands, access sensitive data, and alter systems. Security researchers and vendor advisories reported in-the-wild exploitation, with public proof-of-concept exploit code increasing the risk of broad compromise.
Intrusions linked to the campaign have been associated with Clop data-theft activity, and exploitation was observed from at least early December 2024. Defenders were urged to immediately upgrade affected Cleo products to 5.8.0.24 or later, restrict external access to exposed file transfer servers, and review logs, autorun locations, and other persistence points for suspicious files or commands. The incident adds Cleo software to the list of heavily targeted file transfer platforms exploited for large-scale enterprise breaches.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Cleo states that CVE-2024-50623, affecting Harmony, VLTrader, and LexiCom, was patched in October 2024. Later reporting describes the newer CVE-2024-55956 as similar to this earlier flaw.
CSIRT.SK reports that the Clop ransomware group has used CVE-2024-55956 in data theft attacks against vulnerable Cleo deployments. No specific attack date is provided in the source content.
CSIRT.SK says public proof-of-concept exploit code is available for CVE-2024-55956, increasing the risk to exposed Cleo file transfer systems. The article does not specify when the PoC was released.
CSIRT.SK reports that attackers have been exploiting CVE-2024-55956 since at least 2024-12-03. The flaw affects Cleo Harmony, VLTrader, and LexiCom versions older than 5.8.0.24 and enables unauthenticated file upload and command execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
csirt.sk
Open sourcehuntress.com
Open sourcesupport.cleo.com
Open sourcerapid7.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.