CISA Confirms Active Exploitation of FileZen CVE-2026
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-25108 | Authenticated OS Command Injection in Soliton FileZen Exploited in the Wild Soliton Systems' FileZen contains an OS command injection flaw (CWE-78) that allows a logged-in user to execute arbitrary operating system commands by sending a specially crafted HTTP request. The vulnerability is only triggerable when the FileZen Antivirus Check Option is enabled, so deployments without that option are not exposed to this specific attack path. Successful exploitation yields full command execution on the host, reflected in the high confidentiality, integrity, and availability impacts and the 8.7 (High) CVSS 4.0 score. Any organization running Soliton FileZen with the Antivirus Check Option enabled is affected, particularly those exposing the management or transfer interface to untrusted networks. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2026-02-24, confirming active exploitation in the wild, though no public proof-of-concept is known and ransomware use is listed as unknown. Do: Apply the vendor's mitigations or updated software per Soliton's instructions immediately, as the flaw is confirmed exploited in the wild and carries a BOD 22-01 obligation for US federal agencies. As an interim measure, consider disabling the Antivirus Check Option or restricting network access to the FileZen interface, and review web/application logs for suspicious authenticated HTTP requests or unexpected command execution. Verify current FileZen versions against the vendor/JPCERT advisory to confirm you are on a fixed release. | 8.7 | 5% | KEV |
| nichelikely thousands of deployments, concentrated in Japan (no public install counts available) |
Full article299 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananFeb 25, 2026Vulnerability / Software Security
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a recently disclosed vulnerability in FileZen to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
The vulnerability, tracked as CVE-2026-25108 (CVSS v4 score: 8.7), is a case of operating system (OS) command injection that could allow an authenticated user to execute arbitrary commands via specially crafted HTTP requests.
"Soliton Systems K.K FileZen contains an OS command injection vulnerability when a user logs-in to the affected product and sends a specially crafted HTTP request," CISA said.
According to the Japan Vulnerability Notes (JVN), the vulnerability affects the following versions of the file transfer product -
- Versions 4.2.1 to 4.2.8
- Versions 5.0.0 to 5.0.10
Soliton noted in its advisory that successful exploitation of the issue is only possible when FileZen Antivirus Check Option is enabled, adding it has "received at least one report of damage caused by the exploitation of this vulnerability."
The Japanese technology company also revealed that a bad actor must sign in to the web interface with general user privileges to be able to pull off an attack. Users are advised to update to version 5.0.11 or later to mitigate the threat.
"If you have been attacked or suspect that you have been victimized by this vulnerability, please consider not only updating to V5.0.11 or later, but also changing all user passwords as a precaution, as an attacker can log on with at least one real account," it added.
Federal Civilian Executive Branch (FCEB) agencies are advised to apply the necessary fixes by March 17, 2026, to secure their networks.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/02/cisa-confirms-active-exploitation-of.html