⚡ Exploit-DB.ai CRITICAL
CRITICAL

CVE-2023-40044

Published: March 18, 2026 · Source: National Vulnerability Database (NVD)

⚡ AI Threat Assessment

WS_FTP Server RCE via deserialization — used by thousands of organizations for secure file transfer. Exploited by Cl0p ransomware gang (same group as MOVEit) targeting Managed File Transfer platforms systematically. Apply patches and take offline if internet-exposed.

📋 Official Description

Unauthenticated RCE in Progress WS_FTP Server via .NET deserialization vulnerability in the Ad Hoc Transfer module.

Get Real-Time CVE Alerts

Supernova subscribers receive AI-triaged CVE alerts the moment they're published — before the PoC drops.

Start Supernova — $99/mo →