RW
RiskWire Real-time vulnerability intelligence
This week Pricing Live dashboard
Critical 9.8 KEV + Ransomware

CVE-2024-50623

Aon Named in Termite Ransomware Reports Involving Cleo Vulnerability CVE-2024-50623

Vendor / product: Cleo Harmony, Cleo VLTrader, Cleo LexiCom
Event date: 2026-10-07
Victim organization: Aon
Public PoC: Yes
First tracked by RiskWire: 2026-10-08

CISA KEV catalog

Added to KEV
Federal remediation due
2025-01-03 (643 days overdue)
Ransomware campaign use
Known
CISA description
Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload and download vulnerability that can lead to remote code execution with elevated privileges.
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Named threat actors

Termite

Sources & citations (1)

References

See CVE-2024-50623 in context

RiskWire tracks every exploited CVE this week, cross-referenced against CISA KEV with federal remediation deadlines. Filtered to your vendor stack.

Book a 20-min demo →