CrushFTP warns users to patch unauthenticated access flaw immediately
Customers were advised by CrushFTP to patch their servers right away due to a vulnerability in unauthenticated HTTP(S) port access.
The security issue allows attackers to obtain unauthenticated access to unpatched servers if they are exposed on the Internet over HTTP(S), as the business further clarified in an email sent to clients on Friday (which BleepingComputer was able to view).
Please act right away to patch as soon as possible. We have addressed a vulnerability as of today, March 21, 2025. Every version of CrushFTP v11 was impacted. The previous versions are unaffected. The business cautioned that a CVE would be generated shortly.
The main effect of this issue is that unauthenticated access may result from an open HTTP(S) port read more about CrushFTP warns users to patch ...

