CVE-2024-9999: Progress Software WS_FTP Server

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

In WS_FTP Server versions before 8.8.9 (2022.0.9), an Incorrect Implementation of Authentication Algorithm in the Web Transfer Module allows users to skip the second-factor verification and log in with username and password only.

Affected products

Published 2024-11-12. Last modified 2026-06-17.