Drooid Logo
Back to today’s briefing

Story perspectives

CrushFTP Zero-Day Vulnerability Exposes Admin Access Risk

7/22/2025

27 6

1 of 1

Story summary
  • CrushFTP has revealed a serious zero-day vulnerability, CVE-2025-54309, that enables remote attackers to seize admin access. Discovered on July 18, 2025, this flaw impacts all versions released before July 1. Users are urged to promptly update their systems and reassess security measures to protect against potential threats.