# Cleo Software Actively Being Exploited in the Wild | Huntress

DevFeed: [Cleo Software Actively Being Exploited in the Wild | Huntress](<https://devfeed.tech/articles/cleo-software-actively-being-exploited-in-the-wild-huntress-54599.md>)

Original publisher: [Read original article](<https://www.huntress.com/blog/threat-advisory-oh-no-cleo-cleo-software-actively-being-exploited-in-the-wild>)

Author: Team Huntress

Published: 2025-01-06T21:16:42Z

Content type: article

Language: en

Sources: [Huntress Blog](<https://devfeed.tech/sources/huntress-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Code](<https://devfeed.tech/topics/code.md>), [file](<https://devfeed.tech/topics/file.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [exploitation](<https://devfeed.tech/tags/exploitation.md>), [exploits](<https://devfeed.tech/tags/exploits.md>), [firewall](<https://devfeed.tech/tags/firewall.md>), [huntress](<https://devfeed.tech/tags/huntress.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

## AI overview

Huntress reports that Cleo's LexiCom, VLTransfer, and Harmony file-transfer software is being actively exploited in the wild. The researchers found that the available patch for CVE-2024-50623 does not prevent exploitation and recommend placing internet-exposed systems behind a firewall until a new patch is released.

## Source excerpt

Huntress identified an emerging threat involving Cleo's LexiCom, VLTransfer, and Harmony software, known as CVE-2024-55956, commonly used to manage file transfers. Read more about this emerging threat on the Huntress Blog.