
Cybersecurity authorities and incident response teams are warning organisations to urgently patch a critical vulnerability in CrushFTP, a widely used secure file transfer platform, following active exploitation by cybercriminals.
The vulnerability (CVE-2025-31161), initially discovered by researchers at Outpost24, was responsibly disclosed to CrushFTP on March 13. The vendor began notifying customers on March 21, urging them to update their systems. However, another party reverse-engineered CrushFTP’s fix and publicly revealed the exploit method, prompting a surge in attacks before many customers had time to patch.
On Monday, the Kill ransomware gang claimed to have exploited the flaw and obtained large volumes of sensitive data, threatening to begin extortion campaigns immediately.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed the vulnerability is being actively exploited and has set a patch deadline of April 28 for all federal agencies. Multiple incident response firms, including Huntress, reported live exploitation across industries such as retail, marketing, and semiconductors.
CrushFTP, used by thousands of companies for secure file transfers, is the latest target in a growing trend of mass exploitation campaigns targeting file transfer tools — including previous incidents involving MOVEit, GoAnywhere, and Accellion.
All CrushFTP v10 and v11 instances are affected, and organisations that haven’t applied the latest patch are being urged to do so immediately. Although there are workarounds available, many vulnerable systems remain exposed online, according to scanning efforts by Shadowserver and Censys.
“Anyone unpatched needs to urgently patch,” a CrushFTP spokesperson said. “This vulnerability is now weaponised.”
The situation underscores the ongoing risk posed by supply chain software and third-party tools, especially those used to handle sensitive data across sectors.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543