A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.
CVE-2024-4040
Score elevated to 9.8 because this CVE is listed on the CISA Known Exploited Vulnerabilities catalog (added 2024-04-24), indicating real-world exploitation has been confirmed by US federal agencies. NVD baseline CVSS 9.8 retained for reference. Confidence: HIGH.
- Actively exploited in the wild (CISA-KEV)
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 9.8
- EG Score
- 9.8(high)
- EPSS
- 99.9%
- KEV
- ⚠ Exploited
Published
April 22, 2024
Last Modified
February 26, 2026
Advisory Details (5)
Auto-updated Jun 1, 2026Crush10wiki: Update
https://www.crushftp.com/crush10wiki/Wiki.jsp?page=UpdateCrushFTP warns users to patch exploited zero-day “immediately”
https://www.bleepingcomputer.com/news/security/crushftp-warns-users-to-patch-exploited-zero-day-immediately/GitHub - airbus-cert/CVE-2024-4040: Scanner for CVE-2024-4040 · GitHub
https://github.com/airbus-cert/CVE-2024-4040Unauthenticated CrushFTP Zero-Day Enables Complete Server Compromise | Rapid7 Blog
https://www.rapid7.com/blog/post/2024/04/23/etr-unauthenticated-crushftp-zero-day-enables-complete-server-compromise/Crush11wiki: Update
https://www.crushftp.com/crush11wiki/Wiki.jsp?page=UpdateWeakness Classification(3)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 44× in last 7d / 193× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
Showing the most recent 100 of 344 total refreshes for this CVE.
- 2026-07-22 21:00 UTCGHSA enrichment
- 2026-07-22 19:40 UTCCISA KEV update
- 2026-07-22 16:47 UTCGHSA enrichment
- 2026-07-22 12:35 UTCGHSA enrichment
- 2026-07-22 08:23 UTCGHSA enrichment
- 2026-07-22 04:11 UTCGHSA enrichment
- 2026-07-21 23:59 UTCGHSA enrichment
- 2026-07-21 19:46 UTCGHSA enrichment
- 2026-07-21 15:33 UTCGHSA enrichment
- 2026-07-21 14:37 UTCCISA KEV update
- 2026-07-21 11:20 UTCGHSA enrichment
- 2026-07-21 07:08 UTCGHSA enrichment
- 2026-07-21 02:56 UTCGHSA enrichment
- 2026-07-20 22:44 UTCGHSA enrichment
- 2026-07-20 18:32 UTCGHSA enrichment
- 2026-07-20 14:20 UTCGHSA enrichment
- 2026-07-20 10:08 UTCGHSA enrichment
- 2026-07-20 05:56 UTCGHSA enrichment
- 2026-07-20 01:44 UTCGHSA enrichment
- 2026-07-19 21:31 UTCGHSA enrichment
- 2026-07-19 17:19 UTCGHSA enrichment
- 2026-07-19 13:07 UTCGHSA enrichment
- 2026-07-19 08:55 UTCGHSA enrichment
- 2026-07-19 04:41 UTCGHSA enrichment
- 2026-07-19 00:29 UTCGHSA enrichment
Show 75 moreShow fewer
- 2026-07-18 20:17 UTCGHSA enrichment
- 2026-07-18 16:05 UTCGHSA enrichment
- 2026-07-18 11:52 UTCGHSA enrichment
- 2026-07-18 07:40 UTCGHSA enrichment
- 2026-07-18 03:28 UTCGHSA enrichment
- 2026-07-17 23:16 UTCGHSA enrichment
- 2026-07-17 19:04 UTCGHSA enrichment
- 2026-07-17 14:50 UTCGHSA enrichment
- 2026-07-17 10:38 UTCEG score recompute
- 2026-07-17 10:38 UTCGHSA enrichment
- 2026-07-17 06:26 UTCGHSA enrichment
- 2026-07-17 02:13 UTCGHSA enrichment
- 2026-07-16 22:01 UTCGHSA enrichment
- 2026-07-16 17:49 UTCGHSA enrichment
- 2026-07-16 17:04 UTCCISA KEV update
- 2026-07-16 13:36 UTCGHSA enrichment
- 2026-07-16 09:24 UTCGHSA enrichment
- 2026-07-16 05:11 UTCGHSA enrichment
- 2026-07-16 00:59 UTCGHSA enrichment
- 2026-07-15 20:46 UTCGHSA enrichment
- 2026-07-15 16:49 UTCCISA KEV update
- 2026-07-15 16:31 UTCGHSA enrichment
- 2026-07-15 15:04 UTCCISA KEV update
- 2026-07-15 12:18 UTCGHSA enrichment
- 2026-07-15 08:06 UTCGHSA enrichment
- 2026-07-15 03:54 UTCGHSA enrichment
- 2026-07-14 23:42 UTCGHSA enrichment
- 2026-07-14 19:30 UTCGHSA enrichment
- 2026-07-14 18:05 UTCCISA KEV update
- 2026-07-14 15:17 UTCGHSA enrichment
- 2026-07-14 11:05 UTCGHSA enrichment
- 2026-07-14 06:52 UTCGHSA enrichment
- 2026-07-14 02:40 UTCGHSA enrichment
- 2026-07-13 22:29 UTCEPSS rescore
- 2026-07-13 22:29 UTCGHSA enrichment
- 2026-07-13 18:16 UTCGHSA enrichment
- 2026-07-13 17:07 UTCCISA KEV update
- 2026-07-13 14:04 UTCGHSA enrichment
- 2026-07-13 09:52 UTCGHSA enrichment
- 2026-07-13 05:40 UTCGHSA enrichment
- 2026-07-13 01:28 UTCGHSA enrichment
- 2026-07-12 21:16 UTCGHSA enrichment
- 2026-07-12 17:03 UTCGHSA enrichment
- 2026-07-12 12:52 UTCGHSA enrichment
- 2026-07-12 08:40 UTCGHSA enrichment
- 2026-07-12 04:28 UTCGHSA enrichment
- 2026-07-12 00:16 UTCGHSA enrichment
- 2026-07-11 20:04 UTCGHSA enrichment
- 2026-07-11 15:52 UTCGHSA enrichment
- 2026-07-11 11:40 UTCGHSA enrichment
- 2026-07-11 07:28 UTCGHSA enrichment
- 2026-07-11 03:16 UTCGHSA enrichment
- 2026-07-10 23:04 UTCGHSA enrichment
- 2026-07-10 18:51 UTCGHSA enrichment
- 2026-07-10 17:52 UTCCISA KEV update
- 2026-07-10 14:39 UTCGHSA enrichment
- 2026-07-10 10:27 UTCGHSA enrichment
- 2026-07-10 06:15 UTCGHSA enrichment
- 2026-07-10 02:03 UTCGHSA enrichment
- 2026-07-09 21:51 UTCGHSA enrichment
- 2026-07-09 17:39 UTCGHSA enrichment
- 2026-07-09 13:27 UTCGHSA enrichment
- 2026-07-09 09:14 UTCGHSA enrichment
- 2026-07-09 05:01 UTCGHSA enrichment
- 2026-07-09 00:49 UTCGHSA enrichment
- 2026-07-08 20:36 UTCGHSA enrichment
- 2026-07-08 16:23 UTCGHSA enrichment
- 2026-07-08 12:09 UTCGHSA enrichment
- 2026-07-08 07:57 UTCGHSA enrichment
- 2026-07-08 03:45 UTCGHSA enrichment
- 2026-07-07 23:33 UTCGHSA enrichment
- 2026-07-07 19:21 UTCGHSA enrichment
- 2026-07-07 19:01 UTCCISA KEV update
- 2026-07-07 17:16 UTCCISA KEV update
- 2026-07-07 15:08 UTCGHSA enrichment
Publicly available exploits
(10 references)Working exploit code is in the public domain (1 Metasploit module) (8 GitHub PoCs). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
- GitHub PoCgeniuszly/GenCrushSSTIExploitFirst seen Sep 30, 2024
is a PoC for CVE-2024-4040 tool for exploiting the SSTI vulnerability in CrushFTP
Open source ↗ - GitHub PoCentroychang/CVE-2024-4040First seen Jul 5, 2024
CVE-2024-4040 PoC
Open source ↗ - GitHub PoCgotr00t0day/CVE-2024-4040First seen May 3, 2024
A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.
Open source ↗ - Open source ↗GitHub PoCjakabakos/CVE-2024-4040-CrushFTP-File-Read-vulnerabilityFirst seen May 1, 2024
- GitHub PoCdhammerg/CVE-2024-4040First seen Apr 30, 2024
Exploit CrushFTP CVE-2024-4040
Open source ↗ - GitHub PoCStuub/CVE-2024-4040-SSTI-LFI-PoCFirst seen Apr 25, 2024
CVE-2024-4040 CrushFTP SSTI LFI & Auth Bypass | Full Server Takeover | Wordlist Support
Open source ↗ - Open source ↗GitHub PoCrbih-boulanouar/CVE-2024-4040First seen Apr 25, 2024
- GitHub PoCairbus-cert/CVE-2024-4040First seen Apr 23, 2024
Scanner for CVE-2024-4040
Open source ↗ - Metasploitauxiliary/gather/crushftp_fileread_cve_2024_4040✓ verifiedFirst seen Jan 1, 2024
CrushFTP Unauthenticated Arbitrary File Read
Open source ↗ - Nucleihttp/cves/2024/CVE-2024-4040.yamlFirst seen Jan 1, 2024
CrushFTP VFS - Sandbox Escape LFR
Open source ↗
Related CVEs(same CWE)
Frequently asked(6)
What is CVE-2024-4040?
When was CVE-2024-4040 disclosed?
Is CVE-2024-4040 actively exploited?
What is the CVSS score of CVE-2024-4040?
Which products are affected by CVE-2024-4040?
How do I remediate CVE-2024-4040?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2024-4040
Is Your Infrastructure Affected by CVE-2024-4040?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.