Vulnerability Watch

Forum Discussion

snarang's avatar
snarang
Product Team
3 months ago

CrushFTP Zero-Day Exploited (CVE-2025-54309)

On July 18, CrushFTP warned that a zero-day in its CrushFTP software was being exploited in the wild.

CVEDescriptionCVSSv3
CVE-2025-54309Unprotected Alternate Channel Vulnerability9.0

According to CrushFTP, the vulnerability was first discovered as being exploited on July 18 at 9AM CST, though they caution that exploitation may have “been going on for longer.”

For more information about the vulnerability, including the availability of patches and Tenable product coverage, please visit our blog.

No RepliesBe the first to reply