U.S. Cybersecurity and Infrastructure Security Agency (CISA) has included a recently uncovered severe security weakness affecting CrushFTP in its Known Exploited Vulnerabilities (KEV) directory, as reports surfaced about the ongoing exploitation in the real world.
The flaw enables an unauthorized attacker to potentially assume control of vulnerable instances, as it involves an authentication bypass.
The flaw enables an unauthorized attacker to potentially assume control of vulnerable instances, as it involves an authentication bypass.
