A new zero-day vulnerability in CrushFTP file transfer servers is being actively exploited by cybercriminals, compromising systems around the world. Tracked as CVE-2025-54309, the CrushFTP zero-day vulnerability was first observed in active exploitation on July 18, 2025.
First seen on thecyberexpress.com
Jump to article: thecyberexpress.com/crushftp-zero-day-flaw-cve-2025-54309/
![]()

