Breaking
April 19, 2025

CrushFTP vulnerability exploited in the wild, added to CISA KEV database | usagoldmines.com


  • A critical flaw was discovered in file transfer tool CrushFTP
  • Experts claim the issue was being abused in the wild
  • CISA added the flaw to its KEV catalog

A critical-severity vulnerability plaguing file transfer software CrushFTP was found being actively exploited in the wild.

Earlier this month, it was reported that the software, commonly used by organizations to handle large-scale file transfers, contained an authentication bypass vulnerability which allowed unauthenticated attackers to gain administrative access.

By specifically targeting the crushadmin account, threat actors could abuse the flaw to compromise the target system entirely.

Monitor your credit score with TransUnion starting at $29.95/month

TransUnion is a credit monitoring service that helps you stay on top of your financial health. With real-time alerts, credit score tracking, and identity theft protection, it ensures you never miss important changes. You’ll benefit from a customizable online interface with clear insights into your credit profile. Businesses also benefit from TransUnion’s advanced risk assessment tools.

Preferred partner (What does this mean?)View Deal

CISA adds it to KEV

The flaw is now tracked as CVE-2025-31161, and was given a severity score of 9.8/10 (critical)

It affects CrushFTP versions 10 before 10.8.4 and 11 before 11.3.1. Users are strongly advised to update to these versions immediately, and if they can’t, enabling the DMZ proxy instance can serve as a temporary workaround.

Security researchers have warned that the bugs were used in the wild to install remote management tools like AnyDesk and MeshAgent, The Hacker News reported.

CISA has also picked up on the news, adding the bug to its Known Exploited Vulnerabilities Catalog (KEV). This means that Federal Civilian Executive Branch (FCEB) agencies have a three-week deadline (until April 28) to apply the patch, or stop using CrushFTP entirely.

Cybercriminals often target managed file transfer software vulnerabilities, since they could allow access to sensitive corporate files and databases. In fact, one of the most devastating cyberattacks in recent history happened in 2023, when ransomware operator Cl0p abused a previously unknown SQL injection vulnerability in MOVEit managed file transfer software to breach hundreds of corporations around the world.

A year before that, GoAnywhere MFT was breached and used to steal sensitive data from almost 130 organizations, and in January 2024, the same software was found to be vulnerable to a critical path traversal weakness flaw.

You might also like

​ 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

Is AI bad for music or is it just another step in the auto-tune timeline? erichs211@gmail.com (Eric ...

IPVanish's malware protection confirmed among the best on the market chiara.castro@futurenet.com (Ch...

People Are Reverse Location Searching Photos on ChatGPT, and It Actually Works Jake Peterson | usago...

You Should Try Instagram's New 'Blend' Feature for a Custom Reels Feed Emily Long | usagoldmines.com

Google adds YouTube Music feature to end annoying volume shifts Ryan Whitwam | usagoldmines.com

Buying a USB-C cable? Beware these 6 crucial gotchas | usagoldmines.com

I started ‘vibe coding’ my own apps with AI. I’m absolutely loving it | usagoldmines.com

Samsung just made the best glasses-free 3D monitor I’ve tried yet | usagoldmines.com

Best gaming laptops under $1,000: Expert picks that won’t break the bank | usagoldmines.com

Best DVR for cord-cutters: Tablo vs Zapperbox vs Channels vs the rest | usagoldmines.com

Stanley Cup 2025: How to stream the NHL playoffs & championship | usagoldmines.com

How to Make Peanut Butter in the Vitamix Ascent X5 Allie Chanthorn Reinmann | usagoldmines.com

You freak out when battery life hits 38%, but here's how to extend it and calm the heck down lance.u...

Samsung's latest smartphone has a very simple feature that no other Samsung phone offers right now ...

Microsoft’s “1‑bit” AI model runs on a CPU only, while matching larger systems Kyle Orland | usagold...

Trump official to Katy Perry and Bezos’ fiancée: “You cannot identify as an astronaut” Eric Berger |...

I want to upgrade my laptop to Windows 11. Microsoft won’t let me | usagoldmines.com

Why the Treadmill Can Feel so Much Easier Than Running Outside Beth Skwarecki | usagoldmines.com

Apple TV+ Available at Significantly Lower Price Until Next Week Joe Rossignol | usagoldmines.com

Ryan Gosling is joining the Star Wars universe as an all-new character in 'Starfighter' jacob.krol@f...

Opera Mini stuffs a whole AI assistant into a tiny Android browser erichs211@gmail.com (Eric Hal Sch...

To regenerate a head, you first have to know where your tail is John Timmer | usagoldmines.com

Synology confirms that higher-end NAS products will require its branded drives Kevin Purdy | usagold...

Five Ways to Keep Your Neighbors From Looking Down Into Your Yard Jeff Somers | usagoldmines.com

No Nvidia? No problem - Huawei debuts AI system that's apparently faster than the market leader, the...

Japanese tech giant claims to offer data transmission solution 10x faster than current technologies ...

Here's why you should avoid Vivid mode, even on the best OLED TVs james.davidson@futurenet.com (Jame...

“Lab leak” marketing page replaces federal hub for COVID resources Beth Mole | usagoldmines.com

Regrets: Actors who sold AI avatars stuck in Black Mirror-esque dystopia Ashley Belanger | usagoldmi...

Televes Dinova Boss Mix review: A fantastic, less conspicuous TV antenna | usagoldmines.com

Google’s Overhauled Quick Share UI Previewed Tim | usagoldmines.com

My Favorite Amazon Deal of the Day: The Samsung Galaxy Watch 7 Daniel Oropeza | usagoldmines.com

Apple Sports App Now Lets You Share Game Cards via iMessage and Social Media Joe Rossignol | usagold...

Everything leaving Hulu in May 2025 rowan.davies@futurenet.com (Rowan Davies) | usagoldmines.com

Smells like teen friendship: How scent influences social choices Jennifer Ouellette | usagoldmines.c...

Rover finds hints of an ancient Martian carbon cycle Jacek Krywko | usagoldmines.com

Best live TV streaming service: YouTube TV vs Sling TV vs Hulu + Live TV and the rest | usagoldmine...

Best Chromebooks 2025: Best overall, best battery life, and more | usagoldmines.com

This Ryzen 7 mini PC stacked with 32GB RAM is super cheap: $279 | usagoldmines.com

SHIELD TV Units Getting Hotfix Update to Squash Bugs Tim | usagoldmines.com

You Can Get Both Windows 11 Pro and Office 2019 on Sale for $46 Right Now Pradershika Sharma | usago...

The MacRumors Show: John Gruber Talks Apple Intelligence and the Future of the Company Hartley Charl...

Andor season 2 cast and character guide: who's who in the highly-rated Star Wars TV show's final cha...

State-sponsored actors spotted using ClickFix hacking tool developed by criminals | usagoldmines.co...

Score Acer’s touchscreen AI laptop with 16GB RAM for just $570 | usagoldmines.com

Graphics cards are huge now. Do you need a GPU brace to protect your PC? | usagoldmines.com

HP pays out $4 million in class action suit for false advertising | usagoldmines.com

OpenAI’s latest AI models can ‘think with images’ and combine tools | usagoldmines.com

This Massive Insurance Data Breach Leaked 1.6 Million Users' Information Emily Long | usagoldmines.c...

You Can Get This Kodak Instant Photo Printer on Sale for $70 Right Now Pradershika Sharma | usagoldm...

Nintendo Finally Announced a New Preorder Date for the Switch 2 Jake Peterson | usagoldmines.com

Entertainment venue management giant Legends International reveals major data breach | usagoldmines...

Food retail giant behind several major US supermarket brands confirms data stolen in major ransomwar...

Cupra is all about affordable cars, funky styling, electrified performance Jonathan M. Gitlin | usag...

Trump’s tariffs trigger price hikes at large online retailers Ashley Belanger | usagoldmines.com

Tested! These are the best USB-C cables for charging and data transfers | usagoldmines.com

Over 50 malicious Chrome extensions are secretly spying on you | usagoldmines.com

I block every ad on YouTube. I’m not ashamed to admit it | usagoldmines.com

Discord is making some users verify their age using face and ID scans | usagoldmines.com

How to Quickly Set Up Your New Mac David Nield | usagoldmines.com

This LG OLED TV Is at Its Lowest Price Ever Right Now Pradershika Sharma | usagoldmines.com

Best Apple Deals of the Week: Anker's 20% Sitewide Sale Exclusive to MacRumors Readers, Plus Big Sal...

IBM orders workers back to the office, or face the consequences | usagoldmines.com

Tesla really wants you to buy its Cybertruck, with huge discounts and perks thrown in to clear its g...

7 new movies and TV shows to stream on Netflix, Prime Video, Max, and more this weekend (April 18) t...

From novelty to nuisance: The AI revolution no one wanted is sweeping all before it | usagoldmines....

Super apps deserve a second chance | usagoldmines.com

How to become an intrapreneur in AI headwinds | usagoldmines.com

Nintendo Switch 2 pre-orders will start in the United States on April 24, and the price is not incre...

NYT Connections hints and answers for Saturday, April 19 (game #678) | usagoldmines.com

NYT Strands hints and answers for Saturday, April 19 (game #412) | usagoldmines.com

Quordle hints and answers for Saturday, April 19 (game #1181) | usagoldmines.com

Nintendo raises planned Switch 2 accessory prices amid tariff “uncertainty” Kyle Orland | usagoldmin...

This fast Anker power bank has a built-in USB-C cable — it’s only $16 | usagoldmines.com

This $820 RTX-powered HP gaming laptop is a killer value buy | usagoldmines.com

Pick up Anker’s 5-port USB-C hub with 4K HDMI support for just $25 | usagoldmines.com

These Sennheiser Earbuds Are at Their Lowest Price Right Now Pradershika Sharma | usagoldmines.com

Netflix's New AI Search Feature Will Understand Your Viewing Moods Tim Hardwick | usagoldmines.com

Everything new on Hulu in May 2025 – stream my favorite Pamela Anderson movie, celebrate Star Wars D...

This Tie Fighter stand for the Echo Dot lets your Alexa smart speaker join the dark side jacob.krol@...

US government flags worrying SonicWall flaw, so update now | usagoldmines.com

Assassin’s Creed Shadows is the dad rock of video games, and I love it Samuel Axon | usagoldmines.co...

Sunderfolk review: RPG magic that transports your friends together Kevin Purdy | usagoldmines.com

How Magento 2 Australia Post Shipping Can Boost Your eCommerce Business Anuradha Sinha | usagoldmine...

Seven Strategies for Making the Most Out of Your Small Garden Amanda Blum | usagoldmines.com

AirPods Pro 3 Just Months Away – Here's What We Know Tim Hardwick | usagoldmines.com

HP agrees million-dollar settlement over "false advertising" on PCs, keyboards | usagoldmines.com

Recap: Wheel of Time’s third season balefires its way to a hell of a finish Andrew Cunningham & ...

5 crucial Windows 11 settings I always change ASAP | usagoldmines.com

A critical Erlang/OTP security flaw is "surprisingly easy" to exploit, experts warn - so patch now ...

Rocket Report: Daytona rocket delayed again; Bahamas tells SpaceX to hold up Eric Berger | usagoldmi...

The iPhone 18 is again tipped to get a major performance boost – but price hikes could follow | usa...

The iPhone 16 Pro Max helped me see – with a little help from the Samsung Galaxy S25 Ultra | usagol...

Google "could face breakup" after being found guilty of having illegal ad tech monopolies | usagold...

iPhone Shipments Down 9% in China's Q1 Smartphone Boom Tim Hardwick | usagoldmines.com

Leaked Razr Plus 2025 specs may have revealed everything about Motorola's next flip foldable | usag...

British businesses are getting used to AI at work - but there are still plenty of hurdles to overcom...

The engineer's guide to staying ahead of cyber threats | usagoldmines.com

Yellowjackets season 3 finale made me shocked, surprised and sad – here are 3 things you may have mi...

We just saw the end of the desktop scanner | usagoldmines.com

Leave a Reply