A critical CrushFTP zero-day was reported as actively exploited, allowing an unauthenticated attacker to escape the product’s virtual file system and download files from the underlying system. The flaw was discovered by Simon Garrelou of Airbus CERT, and public reporting said observed attacks primarily targeted organizations in the United States, with some suspicion that the activity was politically motivated.
Defenders were urged to patch immediately because affected deployments could suffer sensitive information disclosure without valid credentials. Guidance pointed users running versions older than 11.1—particularly version 9—to upgrade to fixed releases 10.7.1 or 11.1.0, while CrushFTP’s update documentation provided the vendor’s release path for remediation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
CSIRT.SK urged users of vulnerable CrushFTP versions, especially version 9 and releases older than 11.1, to upgrade immediately to versions 10.7.1 or 11.1.0.
CSIRT.SK said the CrushFTP vulnerability was being actively exploited, with reported attacks primarily targeting entities in the United States and suspected to be politically motivated.
CSIRT.SK reported that Simon Garrelou of Airbus CERT discovered a critical CrushFTP zero-day that lets an unauthenticated attacker escape the virtual file system and download system files.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.