Both CrushFTP, a popular file transfer technology, and Next.js, a widely used React framework for building web applications, have come under scrutiny due to significant vulnerabilities.
Rapid7 has highlighted these issues, emphasizing their potential impact on data security and unauthorized access.
Next.js Vulnerability (CVE-2025-29927):
This critical vulnerability involves improper authorization in middleware, potentially allowing attackers to bypass security checks within Next.js applications.
However, as of March 25, 2025, there are no reported instances of this vulnerability being exploited in the wild.
CrushFTP Vulnerability:
Although not yet assigned a CVE number, CrushFTP has disclosed an unauthenticated HTTP(S) port access vulnerability.
This issue could allow unauthorized access to sensitive data if not addressed promptly. Unlike the Next.js vulnerability, CrushFTP has faced previous exploitation, highlighting the urgency of securing against this threat.
Both vulnerabilities underscore the importance of proactive security measures and timely updates to safeguard against potential threats, especially in technologies that have been targeted previously, like CrushFTP.
As neither vulnerability has been reported exploited in the wild as of now, organizations and developers have a critical window to address these issues before they could be exploited by malicious actors.
Are you from SOC/DFIR Teams? – Analyse Malware, Phishing Incidents & get live Access with ANY.RUN -> Start Now for Free.
Cisco Talos has uncovered an ongoing cyber campaign by the Gamaredon threat actor group, targeting…
Researchers have uncovered a dangerous new mobile banking Trojan dubbed Crocodilus actively targeting financial institutions…
From WannaCry to the MGM Resorts Hack, ransomware remains one of the most damaging cyberthreats…
Cybersecurity researchers have discovered a sophisticated phishing-as-a-service (PhaaS) platform, dubbed "Morphing Meerkat," that leverages DNS…
A recently identified Remote Access Trojan (RAT) has raised alarms within the cybersecurity community due…
PJobRAT, an Android Remote Access Trojan (RAT) first identified in 2019, has resurfaced in a…