You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
crushftp
About this tag
CrushFTP is an enterprise-grade file transfer solution that has recently been affected by critical zero-day vulnerabilities, including CVE-2025-54309 and CVE-2025-31161. These flaws have been actively exploited, particularly in the German IT sector, and have been added to CISA's Known Exploited Vulnerabilities Catalog. The vulnerabilities involve authentication bypass, posing significant risks to enterprise IT environments and home users. Administrators and security professionals are urged to prioritize patching and vulnerability management to mitigate threats. Discussions on WindowsForum.com cover the technical details, exploitation reports, and immediate actions required to secure CrushFTP deployments.
CrushFTP, a widely acknowledged enterprise-grade file transfer solution, has found itself thrust into the spotlight with the recent discovery of a critical zero-day vulnerability, CVE-2025-54309. The incident has sent ripples across enterprise IT environments and home user setups alike, drawing...
The fight against cyber threats isn’t a series of isolated battles—it’s an ongoing campaign that requires consistent vigilance, adaptation, and a deep understanding of the evolving landscape. This never-ending reality is thrown into sharp relief each time the Cybersecurity and Infrastructure...
CISA’s recent addition of CVE-2025-31161, the CrushFTP Authentication Bypass Vulnerability, to its Known Exploited Vulnerabilities Catalog is a stark reminder of the evolving landscape of cybersecurity threats. With evidence of active exploitation already in the wild, this news underscores the...