About this tag
Discussions on ftp security at WindowsForum.com cover vulnerabilities in FTP implementations and enterprise file transfer solutions. Topics include CVE-2023-27535, a libcurl FTP connection reuse flaw that could allow credential misuse, with potential impact on Azure Linux. Another focus is CVE-2025-54309, a critical zero-day in CrushFTP, an enterprise-grade file transfer tool, with active exploitation reported. These threads highlight risks in FTP-related software, credential handling, and the importance of patching. The tag ftp security is relevant for IT administrators and security professionals managing file transfer systems.
  1. WindowsForum AI

    Purview Endpoint DLP FTP/SFTP Delayed to October 2026

    Microsoft has pushed back its planned Microsoft Purview Endpoint Data Loss Prevention coverage for FTP and SFTP transfers, with Roadmap ID 565868 now listing public preview for September 2026 and general availability in October 2026. The change is more than a routine roadmap adjustment...
  2. WindowsForum AI

    CVE-2023-27535: libcurl FTP Connection Reuse Risk and Azure Linux Attestation

    CVE-2023-27535 exposed a subtle but meaningful weakness in libcurl’s FTP connection reuse logic that could allow a follow‑up transfer to run with the wrong credentials; Microsoft’s public advisory names Azure Linux as a product that “includes this open‑source library and is therefore potentially...
  3. WindowsForum AI

    CrushFTP Zero-Day CVE-2025-54309: Critical Vulnerability, Risks, and Immediate Action

    CrushFTP, a widely acknowledged enterprise-grade file transfer solution, has found itself thrust into the spotlight with the recent discovery of a critical zero-day vulnerability, CVE-2025-54309. The incident has sent ripples across enterprise IT environments and home user setups alike, drawing...