CVE-2024-50623
Exploited in the Wild
✓ Confirmed 0-Day
Triaged: March 5, 2026
6 articles
EPSS Score
Source: FIRST.org · 2026-05-24
94.01%
probability
This CVE has a 94.01% probability
of being exploited in the next 30 days.
0%
Top 99.9th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Attack Intelligence
Exploits & PoC
watchtowrlabs/CVE-2024-50623
Cleo Unrestricted file upload and download PoC (CVE-2024-50623)
25
verylazytech/CVE-2024-50623
CVE-2024-50623 POC - Cleo Unrestricted file upload and download
7
iSee857/Cleo-CVE-2024-50623-PoC
Cleo 远程代码执行漏洞批量检测脚本(CVE-2024-50623)
5
congdong007/CVE-2024-50623-poc
PoC CVE-2024-50623 — congdong007/CVE-2024-50623-poc
0
4 repos — triés par ⭐
Rechercher sur GitHub ↗
Oracle patches EBS zero-day exploited in Clop data theft attacks
BleepingComputer
Oct 05, 2025
Cleo patches critical zero-day exploited in data theft attacks
BleepingComputer
Dec 12, 2024
American Airlines subsidiary Envoy confirms Oracle data theft attack
BleepingComputer
Oct 17, 2025
Clop exploited Oracle zero-day for data theft since early August
BleepingComputer
Oct 07, 2025
Harvard investigating breach linked to Oracle zero-day exploit
BleepingComputer
Oct 13, 2025
Signal Intelligence
Confidence
92%
EPSS
94.01%
Mentions
6
Last Seen
Oct 17, 2025
CNA Information
Analyst Note
Article [2] explicitly names CVE-2024-50623 as a 'critical zero-day exploited in data theft attacks' by Clop threat actors. The CVE was published 2024-10-27 and articles confirm active exploitation in the wild, with the patch released simultaneously or immediately after disclosure, meeting the zero-day criteria.
Threat Actors 28
Lazarus Group
apt_group
Information theft and espionage
🇰🇵 KP
APT 29
apt_group
Information theft and espionage
🇷🇺 RU
Cobalt
apt_group
Financial crime
🇷🇺 RU
APT 28
apt_group
Information theft and espionage
🇷🇺 RU
Harvester
apt_group
Information theft and espionage
Unknown
Evil Corp
apt_group
Financial crime
🇷🇺 RU
INDRIK SPIDER
apt_group
Financial gain
🇷🇺 RU
Hacking Team
apt_group
🇮🇹 IT
SCATTERED SPIDER
apt_group
Financial crime
🇺🇸 US
Tick
apt_group
Information theft and espionage
🇨🇳 CN
TA505
apt_group
Financial gain
🇷🇺 RU
Infy
apt_group
Information theft and espionage
🇮🇷 IR
Group 27
apt_group
Information theft and espionage
🇨🇳 CN
Attor
apt_group
🇷🇺 RU
Returned Libra
apt_group
🇨🇳 CN
Blue Termite
apt_group
Information theft and espionage
🇨🇳 CN
VICE SPIDER
apt_group
🇷🇺 RU
Rocke
apt_group
🇨🇳 CN
APT 6
apt_group
Information theft and espionage
🇨🇳 CN
Red Dev 17
apt_group
🇨🇳 CN
Red October
apt_group
🇷🇺 RU
The White Company
apt_group
Information theft and espionage
🇨🇳 CN
Shadow Network
apt_group
Information theft and espionage
🇨🇳 CN
Mana Team
apt_group
🇨🇳 CN
Iron Group
apt_group
Information theft and espionage
🇨🇳 CN
Big Panda
apt_group
🇨🇳 CN
APT 5
apt_group
Information theft and espionage
🇨🇳 CN
Cyber Alliance
apt_group
🇺🇦 UA
Triage Info
Decided atMar 05, 2026