<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://exploit-radar.com/en/flux/categories/mft.xml</id>
  <title>Exploit Radar: Managed file transfer (MFT)</title>
  <subtitle>The latest additions to CISA’s catalog of exploited vulnerabilities in the “Managed file transfer (MFT)” category (indicative classification).</subtitle>
  <link rel="self" type="application/atom+xml" href="https://exploit-radar.com/en/flux/categories/mft.xml"/>
  <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/produits/mft/"/>
  <updated>2026-08-27T00:00:00Z</updated>
  <author><name>Exploit Radar</name></author>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2023-49105/</id>
    <title>CVE-2023-49105 — ownCloud Server</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2023-49105/"/>
    <updated>2026-08-27T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from ownCloud; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on August 27, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-28318/</id>
    <title>CVE-2026-28318 — SolarWinds Serv-U</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-28318/"/>
    <updated>2026-06-05T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from SolarWinds; if none are available, stop using the product. For cloud services, follow the guidance from SolarWinds. CISA deadline: 14 days. Added to CISA’s catalog of exploited vulnerabilities on June 5, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2025-47813/</id>
    <title>CVE-2025-47813 — Wing FTP Server</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2025-47813/"/>
    <updated>2026-03-16T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Wing FTP Server; if none are available, stop using the product. For cloud services, follow the guidance from Wing FTP Server. CISA deadline: 14 days. Added to CISA’s catalog of exploited vulnerabilities on March 16, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-25108/</id>
    <title>CVE-2026-25108 — Soliton Systems FileZen</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-25108/"/>
    <updated>2026-02-24T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Soliton Systems; if none are available, stop using the product. For cloud services, follow the guidance from Soliton Systems. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on February 24, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2025-14611/</id>
    <title>CVE-2025-14611 — Gladinet CentreStack / Triofox</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2025-14611/"/>
    <updated>2025-12-15T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Gladinet; if none are available, stop using the product. For cloud services, follow the guidance from Gladinet. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on December 15, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2025-12480/</id>
    <title>CVE-2025-12480 — Gladinet CentreStack / Triofox</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2025-12480/"/>
    <updated>2025-11-12T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Gladinet; if none are available, stop using the product. For cloud services, follow the guidance from Gladinet. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on November 12, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2025-11371/</id>
    <title>CVE-2025-11371 — Gladinet CentreStack / Triofox</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2025-11371/"/>
    <updated>2025-11-04T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Gladinet; if none are available, stop using the product. For cloud services, follow the guidance from Gladinet. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on November 4, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2025-10035/</id>
    <title>CVE-2025-10035 — Fortra GoAnywhere MFT</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2025-10035/"/>
    <updated>2025-09-29T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Fortra; if none are available, stop using the product. For cloud services, follow the guidance from Fortra. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on September 29, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2025-54309/</id>
    <title>CVE-2025-54309 — CrushFTP</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2025-54309/"/>
    <updated>2025-07-22T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from CrushFTP; if none are available, stop using the product. For cloud services, follow the guidance from CrushFTP. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on July 22, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2025-47812/</id>
    <title>CVE-2025-47812 — Wing FTP Server</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2025-47812/"/>
    <updated>2025-07-14T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Wing FTP Server; if none are available, stop using the product. For cloud services, follow the guidance from Wing FTP Server. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on July 14, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2025-30406/</id>
    <title>CVE-2025-30406 — Gladinet CentreStack / Triofox</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2025-30406/"/>
    <updated>2025-04-08T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Gladinet; if none are available, stop using the product. For cloud services, follow the guidance from Gladinet. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on April 8, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2025-31161/</id>
    <title>CVE-2025-31161 — CrushFTP</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2025-31161/"/>
    <updated>2025-04-07T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from CrushFTP; if none are available, stop using the product. For cloud services, follow the guidance from CrushFTP. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on April 7, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2024-55956/</id>
    <title>CVE-2024-55956 — Cleo Harmony / VLTrader / LexiCom</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2024-55956/"/>
    <updated>2024-12-17T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Cleo; if none are available, stop using the product. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on December 17, 2024.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2024-50623/</id>
    <title>CVE-2024-50623 — Cleo Harmony / VLTrader / LexiCom</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2024-50623/"/>
    <updated>2024-12-13T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Cleo; if none are available, stop using the product. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on December 13, 2024.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2024-11680/</id>
    <title>CVE-2024-11680 — ProjectSend</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2024-11680/"/>
    <updated>2024-12-03T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from ProjectSend; if none are available, stop using the product. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on December 3, 2024.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2023-45727/</id>
    <title>CVE-2023-45727 — North Grid Proself</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2023-45727/"/>
    <updated>2024-12-03T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from North Grid; if none are available, stop using the product. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on December 3, 2024.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2024-28995/</id>
    <title>CVE-2024-28995 — SolarWinds Serv-U</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2024-28995/"/>
    <updated>2024-07-17T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from SolarWinds; if none are available, stop using the product. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on July 17, 2024.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2024-23692/</id>
    <title>CVE-2024-23692 — Rejetto HTTP File Server (HFS)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2024-23692/"/>
    <updated>2024-07-09T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Rejetto; if none are available, stop using the product. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on July 9, 2024.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2024-4040/</id>
    <title>CVE-2024-4040 — CrushFTP</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2024-4040/"/>
    <updated>2024-04-24T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from CrushFTP; if none are available, stop using the product. CISA deadline: 7 days. Added to CISA’s catalog of exploited vulnerabilities on April 24, 2024.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2023-49103/</id>
    <title>CVE-2023-49103 — ownCloud Server</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2023-49103/"/>
    <updated>2023-11-30T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from ownCloud; if none are available, stop using the product. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on November 30, 2023.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2023-40044/</id>
    <title>CVE-2023-40044 — Progress WS_FTP Server</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2023-40044/"/>
    <updated>2023-10-05T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Progress; if none are available, stop using the product. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on October 5, 2023.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2023-24489/</id>
    <title>CVE-2023-24489 — Citrix ShareFile</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2023-24489/"/>
    <updated>2023-08-16T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Citrix; if none are available, stop using the product. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on August 16, 2023.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2023-34362/</id>
    <title>CVE-2023-34362 — Progress MOVEit Transfer</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2023-34362/"/>
    <updated>2023-06-02T00:00:00Z</updated>
    <summary type="text">Apply the security update from Progress. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on June 2, 2023.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2022-47986/</id>
    <title>CVE-2022-47986 — IBM Aspera Faspex</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2022-47986/"/>
    <updated>2023-02-21T00:00:00Z</updated>
    <summary type="text">Apply the security update from IBM. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on February 21, 2023.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2023-0669/</id>
    <title>CVE-2023-0669 — Fortra GoAnywhere MFT</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2023-0669/"/>
    <updated>2023-02-10T00:00:00Z</updated>
    <summary type="text">Apply the security update from Fortra. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on February 10, 2023.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2014-6287/</id>
    <title>CVE-2014-6287 — Rejetto HTTP File Server (HFS)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2014-6287/"/>
    <updated>2022-03-25T00:00:00Z</updated>
    <summary type="text">Apply the security update from Rejetto. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on March 25, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2021-22941/</id>
    <title>CVE-2021-22941 — Citrix ShareFile</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2021-22941/"/>
    <updated>2022-03-25T00:00:00Z</updated>
    <summary type="text">Apply the security update from Citrix. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on March 25, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2021-35247/</id>
    <title>CVE-2021-35247 — SolarWinds Serv-U</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2021-35247/"/>
    <updated>2022-01-21T00:00:00Z</updated>
    <summary type="text">Apply the security update from SolarWinds. CISA deadline: 14 days. Added to CISA’s catalog of exploited vulnerabilities on January 21, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2021-35211/</id>
    <title>CVE-2021-35211 — SolarWinds Serv-U</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2021-35211/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from SolarWinds. CISA deadline: 14 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2021-27101/</id>
    <title>CVE-2021-27101 — Kiteworks (Accellion) FTA (File Transfer Appliance)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2021-27101/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from Kiteworks (Accellion). CISA deadline: 14 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2021-27103/</id>
    <title>CVE-2021-27103 — Kiteworks (Accellion) FTA (File Transfer Appliance)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2021-27103/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from Kiteworks (Accellion). CISA deadline: 14 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2021-27104/</id>
    <title>CVE-2021-27104 — Kiteworks (Accellion) FTA (File Transfer Appliance)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2021-27104/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from Kiteworks (Accellion). CISA deadline: 14 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2021-27102/</id>
    <title>CVE-2021-27102 — Kiteworks (Accellion) FTA (File Transfer Appliance)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2021-27102/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from Kiteworks (Accellion). CISA deadline: 14 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
</feed>
