New CrushFTP zero-day exploited in attacks to hijack servers

New CrushFTP zero-day exploited in attacks to hijack servers










CrushFTP is warning that threat actors are actively exploiting a zero-day vulnerability tracked as CVE-2025-54309, which allows attackers to gain administrative access via the web interface on vulnerable servers. […]






Lawrence Abrams





Go to bleepingcomputer





Posted

in

,

by