New Cleo Harmony Vulnerability: Exploit Code Now Public
A security vulnerability has been identified in Cleo Harmony, a widely used managed file transfer platform, that allows remote attackers to bypass authentication controls through manipulation of an authentication mechanism known as 'argument bearer' handling. Exploit code for this flaw has now been published, meaning attackers no longer need deep technical expertise to attempt to exploit it.
Cleo's file transfer products have previously been targeted in real-world attacks, including incidents linked to data theft and ransomware operations. Because authentication bypass vulnerabilities can allow attackers to gain unauthorised access to systems without needing valid credentials, this flaw is particularly concerning for any organisation using Cleo Harmony to move sensitive files between business partners, customers, or internal systems.
Businesses using Cleo Harmony should treat this as an urgent issue. Vendors typically release patches once such vulnerabilities are disclosed, and applying updates promptly is the most effective way to close the gap before attackers exploit it further. Given the public availability of exploit code, the window between disclosure and active exploitation is likely to be short.