CrushFTP Servers Hit by Critical Zero-Day Vulnerability CVE-2025-54309
A zero-day flaw in CrushFTP (CVE-2025-54309) is being exploited via HTTP/S, targeting outdated servers. Patch now to avoid unauthorized access.
A zero-day flaw in CrushFTP (CVE-2025-54309) is being exploited via HTTP/S, targeting outdated servers. Patch now to avoid unauthorized access.
CISA adds CVE-2025-31161 to its catalog, highlighting a critical authentication bypass in CrushFTP. This flaw allows attackers to exploit admin ...
#1 Trending Cybersecurity News and Magazine
The Cyber Express is a handbook for all stakeholders of the internet that provides information security professionals with the latest news, updates and knowledge they need to combat cyber threats.
We’re remote friendly, with office locations around the world:
San Francisco, Atlanta, Rome,
Dubai, Mumbai, Bangalore, Hyderabad, Singapore, Jakarta, Sydney, and Melbourne
Headquarters:
The Cyber Express LLC
10080 North Wolfe Road, Suite SW3-200, Cupertino, CA, US 95014
India Office:
Cyber Express Media Network
HD-021, 4th Floor, C Wing, Building No.4. Nesco IT Park, WE Highway, Goregaon East, Mumbai, Maharashtra, India – 4000063
© 2026 The Cyber Express - Cybersecurity News and Magazine.
© 2026 The Cyber Express - Cybersecurity News and Magazine.