
Cerberus FTP Server is a secure and reliable file transfer solution designed for Windows, offering advanced support for SSH, SFTP, and FTPS protocols. It provides strong protection and flexible configuration options, making it a dependable choice for professional and business environments.
Cerberus FTP Server delivers industrial-strength security through SSL/TLS encryption alongside powerful FTP server performance, without compromising ease of use. Created with efficiency in mind, it requires minimal CPU and memory resources and provides a user-friendly interface that can be easily accessed or hidden via the system tray.
This server offers robust management and security features for diverse IT environments. It can listen for connections on multiple interfaces (ideal for multi-homed PCs) and seamlessly integrate with Windows NT user databases or Active Directory for streamlined user management.
Operating as an NT service, it ensures continuous availability and can resume failed transfers, minimizing disruptions. Administrators gain granular control with an easy-to-use manager for user access to files and operations. Furthermore, vital settings like connection limits, timeouts, and IP access can be precisely controlled, along with a variety of other configurations.
In addition, Cerberus FTP Server provides detailed connection statistics and robust logging capabilities, offering administrators comprehensive insights into server activity and performance.
Cerberus FTP Server Features:
- Powerful SFTP Server. FTP, FTPS, SSH, SFTP, and HTTPS web client access, plus Event Notification, Automated Processing, Auditing and Reporting, and Ad Hoc File Transfers.
- Confidence. Robust file transfer integrity checking using strong checksums based on SHA-512, SHA-256, or SHA-1 cryptographic hashes
- Security: Added Protection against Intrusion. Configuration and Security Summary. Specify SSL ciphers to include or exclude. Restrict login by protocol. Password Policy Settings
- IP Whitelist and Blacklist, Automatic Account Lockout. Temporary User Accounts. AD FTP Security Groups Certificate Revocation Lists (CRLs). Client Certificate Verification. SSH2 Public Key Authentication
- HIPAA Compliant, FIPS 140-2 Validated. Exceeds industry standards with FIPS 140-2. Also provides the necessary access controls to meet compliance regulations. Ensures data is protected from unauthorized access and logs all commands and file activity for auditing.
- Manage and authenticate user accounts from built-in users and groups, Active Directory, and LDAP, and control authentication order priority with the new authentication chaining control.
- Create custom Virtual Directories for individual Active Directory and LDAP users.
- Enhanced performance on Windows Server. Low memory utilization, native 64-bit, and full IPv6 support.
- Logging and Auditing. Rolling log files with configurable size limits, Syslog Integration, detailed TLS/SSL cipher and bit strength per connection. Automatic logging of all commands and file access creates a complete audit trail.
- Detailed Statistics. Maintains statistical information about connections and file transfers. Allows creation of detailed reports of server usage.
- Superior Manageability. SOAP control API, Windows Service Support, and support for Microsoft’s Hyper-V and VMware’s ESX platforms.
- Maintain full access to the UI when running as a service
- Administrators can use the auto-blocking feature. It helps to prevent DoS (Denial of Service).
- IP Manager CIDR support
Cerberus FTP Server Other Features:
- Simultaneous FTP, SFTP, and FTPS for a single interface
- Custom Virtual Directories for individual Active Directory and LDAP users
- Require Secure Connections on a per-user basis
- Password Policy Settings
- Automatic Account Lockout
- IP Manager CIDR support
- Specify SSL ciphers to include or exclude
- Support for RSA, DSA, and Elliptic Curve public and private keys
- Support for Ephemeral Diffie-Hellman key exchange
- Block FXP and reserved ports for PASV connections
- Require Active Directory Security Group Membership
- UTF-8 – Display filenames in foreign languages with their native charset
- Taskbar icon control and status indicator
- Connections limit and timeout controls
- Transfer and connection statistics
- Hidden server mode (Hides server window)
- Fine-Grained Directory Access Restrictions
- IPv6 Support
What’s New in Cerberus FTP Server 2026.1 (2026-03-31):
New Features
- Cerberus has been updated to achieve FIPS 140-3 compliance, enhancing support for regulated environments and ensuring data protection. This change comes ahead of the September 2026 retirement of FIPS 140-2.
- Added support for ETM (Encrypt-Then-MAC) algorithms (hmac-sha2-256-etm and hmac-sha2-512-etm) to SFTP, hardening the server against modern vulnerabilities like the recent Terrapin attacks
- Banned usernames can no longer be requested as new native accounts.
- CSV user import now acknowledges blank passwords and requires admin confirmation before importing these users.
- HTTP/S listeners can now optionally remove the login prompt when SAML SSO is configured, streamlining authentication for SSO-only deployments. The login form is automatically displayed if SSO is unavailable to prevent user lockout.
- Upgraded cURL to 8.18.0 to address several low CVEs (CVE-2025-15224, CVE-2025-15079, CVE-2025-14819, CVE-2025-14524, CVE-2025-10966) as well as medium CVEs (CVE-2025-14017, CVE-2025-13034).
- Upgraded libssh2 to 1.11.1.
- Upgraded log4cxx to 1.6.1.
Improvements
- SSH/SFTP cipher, MAC, and key exchange algorithms are now displayed in order from most secure to least secure in the protocol security settings.
Fixes
- Long filenames now wrap in the file browser, instead of being truncated, for better readability.
- Server updates are no longer blocked when EULA changes are included; the admin acceptance checkbox enables successful silent installations for all software and EULA updates.
- SSO users may now be deleted from the cache. A new ability to remove all inactive users from provisioning has been added.
- License expiration events now provide proactive alerts, allowing admins to configure automated email notifications up to one year in advance to prevent unexpected service interruptions.
- Local privilege escalation (LPE) vulnerability where BUILTIN\Users had write access to the update installers directory.
Official Homepage – https://www.cerberusftp.com
Supported Operating Systems:
- Windows Server 2022
- Windows Server 2019
- Windows Server 2016
- Windows 11, 10, 8, 7
Size: 39.8 MB
DOWNLOAD Cerberus FTP Server 26 for Windows 64-bit
DOWNLOAD Cerberus FTP Server 11.3.7 for Windows 32-bit

