{"id":12220,"date":"2026-04-18T10:03:39","date_gmt":"2026-04-18T10:03:39","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/04\/18\/nearly-6-million-internet-facing-ftp-servers-still-exposed-in-2026-censys-warns\/"},"modified":"2026-04-18T10:03:39","modified_gmt":"2026-04-18T10:03:39","slug":"nearly-6-million-internet-facing-ftp-servers-still-exposed-in-2026-censys-warns","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/04\/18\/nearly-6-million-internet-facing-ftp-servers-still-exposed-in-2026-censys-warns\/","title":{"rendered":"Nearly 6 Million Internet-Facing FTP Servers Still Exposed in 2026, Censys Warns"},"content":{"rendered":"<p>    Nearly 6 Million Internet-Facing FTP Servers Still Exposed in 2026, Censys Warns<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>According to a recent April 2026 report by security researcher Himaja Motheram at Censys, just under 6 million <a href=\"https:\/\/cybersecuritynews.com\/monsta-ftp-remote-code-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">internet-facing hosts are still running the File Transfer Protocol (FTP).<\/a><\/p>\n<p>While this marks a significant 40% decline from the 10.1 million servers observed in 2024, the presence of this decades-old protocol continues to pose an exposure risk due to widespread insecure default configurations.<\/p>\n<p>The Censys report highlights that the dominant story of FTP exposure in 2026 is not purpose-built file transfer infrastructure, but rather an accumulation of platform defaults on shared hosting networks and broadband providers.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-the-state-of-encryption-and-regional-risks\"><strong>The State of Encryption and Regional Risks<\/strong><\/h2>\n<p>When it comes to securing these servers, the data reveals a mixed landscape. Censys found that roughly 58.9% of observed FTP hosts completed a <a href=\"https:\/\/cybersecuritynews.com\/staying-on-top-of-tls-attacks\/\" target=\"_blank\" rel=\"noreferrer noopener\">Transport Layer Security (TLS) handshake<\/a>, meaning they support encrypted connections.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhWc-bX8wtbk5jYfQ6cHUVgciSH4cHrtGVqK_BKuXTt2ioxECZ9sun64nr6JUsCYJ1106UQjEKLX460wfUXAYt9lgYvSTZBdASavVbcvypLenfXFwWM-BBDZG808wIvaZPBRj_L8ZYjVVZg31IywwcgPAPy0ybSq42TsX5HBTLGdGpROZnNgemqo273nZs\/s1600\/Screenshot%25202026-04-17%2520130236%2520%25281%2529.webp?ssl=1\" alt=\"FileZilla server responding with a funny TLS response(Source: Censys)\"><figcaption class=\"wp-element-caption\"><em>FileZilla server responding with a funny TLS response(Source: Censys)<\/em><\/figcaption><\/figure>\n<p>However, this leaves approximately 2.45 million hosts without observed evidence of encryption, potentially allowing them to transmit files and credentials in cleartext.<\/p>\n<p>The lack of encryption adoption varies significantly by region. According to Censys data, mainland China and South Korea have the lowest TLS adoption rates among the top 10 hosting countries, at 17.9% and 14.5%, respectively.<\/p>\n<p>Meanwhile, Japan accounts for 71% of all FTP servers globally that still rely on outdated, deprecated legacy <a href=\"https:\/\/cybersecuritynews.com\/tor-adopts-galois-onion-encryption\/\" target=\"_blank\" rel=\"noreferrer noopener\">encryption protocols<\/a> such as TLS 1.0 and 1.1.<\/p>\n<p>The security posture of these 6 million servers is heavily influenced by the default settings of the software daemons running them.<\/p>\n<p><strong>Key technical observations from the Censys report include:<\/strong><\/p>\n<ul class=\"wp-block-list\">\n<li>\n<strong>Pure-FTPd Dominance:<\/strong> Operating on roughly 1.99 million services, this is the most common FTP daemon, largely driven by its inclusion as a default in cPanel hosting environments.\n<\/li>\n<li>\n<strong>The IIS FTP Configuration Trap:<\/strong> Over 150,000 <a href=\"https:\/\/cybersecuritynews.com\/badiis-malware-compromising-iis-servers\/\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft IIS FTP services<\/a> return a \u201c534\u201d error response, indicating TLS was never configured.<\/p>\n<p>While IIS defaults to a policy that appears to require encryption, it does not bind a security certificate upon a fresh installation. <\/p>\n<p>Consequently, <a href=\"https:\/\/cybersecuritynews.com\/lynx-gateway-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">the server accepts cleartext credentials<\/a>, even though the configuration appears to enforce TLS.\n<\/li>\n<li>\n<strong>Hidden Nonstandard Ports:<\/strong> Relying only on port 21 scans miss a significant portion of the attack surface. <\/p>\n<p>Tens of thousands of FTP services run on alternate ports, such as 10397 or 2121, often tied to specific telecom operations or network-attached storage devices.<\/li>\n<\/ul>\n<h2 class=\"wp-block-heading\" id=\"h-mitigation-and-hardening-strategies\"><strong>Mitigation and Hardening Strategies<\/strong><\/h2>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjsr3i2hlehPh3kVg8ltuT0bqF9Iq8kviM-3PcIlaycBjnO6gSRkdyPna1Oqu5AUG16DVkY80p5048Ruu-O59bkY9M268RCpGBKkTACaYnwI2CDU1L8-x36X93_nh-37Vv-sh6W1DB94fBiB3lNwMOcVi5a0SoMKtB1Xuv8jA37aMXt0vYPwmZD_SUowYA\/s1600\/Screenshot%25202026-04-17%2520130214%2520%25281%2529.webp?ssl=1\" alt=\"2.35 Million FTP Services With No Evidence of TLS(Source: Censys)\"><figcaption class=\"wp-element-caption\"><em>2.35 Million FTP Services With No Evidence of TLS(Source: Censys)<\/em><\/figcaption><\/figure>\n<p>For enterprise defenders and infrastructure administrators, <a href=\"https:\/\/censys.com\/blog\/ftp-exposure-brief\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Censys strongly recommends evaluating<\/a> whether FTP is truly necessary before attempting to harden it.<\/p>\n<p><strong>Organizations should consider the following mitigation strategies:<\/strong><\/p>\n<ul class=\"wp-block-list\">\n<li>\n<strong>Migrate to Secure Alternatives:<\/strong> Whenever possible, <a href=\"https:\/\/cybersecuritynews.com\/titan-file-transfer-server-flaws\/\" target=\"_blank\" rel=\"noreferrer noopener\">replace FTP with SSH File Transfer Protocol (SFTP)<\/a>, which encrypts credentials and data by default over port 22.\n<\/li>\n<li>\n<strong>Enforce Explicit TLS:<\/strong> If legacy FTP infrastructure must remain online, administrators should configure their daemons to enforce Explicit TLS (FTPS) and refuse cleartext connections.\n<\/li>\n<li>\n<strong>Fix IIS Certificate Bindings:<\/strong> Windows Server administrators using IIS FTP must ensure that a valid certificate is bound to the FTP site and verify that the SSL policy actively enforces encryption.<\/li>\n<\/ul>\n<p>Ultimately, while the internet\u2019s reliance on FTP is slowly shrinking, millions of instances continue to run quietly in the background.<\/p>\n<p>As Censys warns, the primary risk is not advanced <a href=\"https:\/\/cybersecuritynews.com\/hackers-launch-zero-day-attacks-to-exploits-corrupted-files-to-evade-security-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">zero-day attacks<\/a>, but the simple failure to update default configurations that leave systems unnecessarily exposed.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/ftp-servers-exposed\/\">Nearly 6 Million Internet-Facing FTP Servers Still Exposed in 2026, Censys Warns<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/ftp-servers-exposed\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Nearly 6 Million Internet-Facing FTP Servers Still Exposed in 2026, Censys Warns According to a recent April 2026 report by security researcher Himaja Motheram at Censys, just under 6 million internet-facing hosts are still running the File Transfer Protocol (FTP). While this marks a significant 40% decline from the 10.1 million servers observed in 2024, [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1636,129,63],"tags":[130],"class_list":["post-12220","post","type-post","status-publish","format-standard","hentry","category-cyber-attack-news","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12220"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=12220"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12220\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=12220"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=12220"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=12220"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}