cognitive cybersecurity intelligence

News and Analysis

Search

CISA Warns of CrushFTP Authentication Bypass Vulnerability Exploited in Attacks

CISA Warns of CrushFTP Authentication Bypass Vulnerability Exploited in Attacks

CISA has added a critical authentication bypass vulnerability (CVE-2025-31161) in CrushFTP (versions 10.0.0-10.8.3 and 11.0.0-11.3.0) to its KEV Catalog. With a CVSS score of 9.8, this flaw allows remote, unauthenticated access, posing high risks. CrushFTP issued patches on March 21, 2025. Organizations are urged to urgently update their installations to mitigate risks.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts