CrushFTP warns users to patch unauthenticated access flaw immediately

Customers were advised by CrushFTP to patch their servers right away due to a vulnerability in unauthenticated HTTP(S) port access.

The security issue allows attackers to obtain unauthenticated access to unpatched servers if they are exposed on the Internet over HTTP(S), as the business further clarified in an email sent to clients on Friday (which BleepingComputer was able to view).

Please act right away to patch as soon as possible. We have addressed a vulnerability as of today, March 21, 2025. Every version of CrushFTP v11 was impacted. The previous versions are unaffected. The business cautioned that a CVE would be generated shortly.

The main effect of this issue is that unauthenticated access may result from an open HTTP(S) port read more about CrushFTP warns users to patch unauthenticated access flaw immediately.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *