criticalKEV
CVE-2024-4040
CrushFTP VFS sandbox escape via server-side template injection - unauthenticated file read / RCE
- Severity
- critical
- Affected product
- CrushFTP
- Affected versions
- CrushFTP < 10.7.1
- Fixed in
- CrushFTP 10.7.1 / 11.1.0
- CISA KEV
- Listed as a known exploited vulnerability
- Added to NewScan
- 2026-08-02
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the CrushFTP appliance and reports this CVE when the detected version falls inside the affected range below.
The 11.x line fixed this in 11.1.0; the `lt` gate is the 10.x boundary, so an 11.0.x banner is reported as an advisory rather than a gated finding.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →