CISA flags exploited FileZen command injection bug, patch now! (CVE-2026-25108)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-25108 | Authenticated OS Command Injection in Soliton FileZen Exploited in the Wild Soliton Systems' FileZen contains an OS command injection flaw (CWE-78) that allows a logged-in user to execute arbitrary operating system commands by sending a specially crafted HTTP request. The vulnerability is only triggerable when the FileZen Antivirus Check Option is enabled, so deployments without that option are not exposed to this specific attack path. Successful exploitation yields full command execution on the host, reflected in the high confidentiality, integrity, and availability impacts and the 8.7 (High) CVSS 4.0 score. Any organization running Soliton FileZen with the Antivirus Check Option enabled is affected, particularly those exposing the management or transfer interface to untrusted networks. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2026-02-24, confirming active exploitation in the wild, though no public proof-of-concept is known and ransomware use is listed as unknown. Do: Apply the vendor's mitigations or updated software per Soliton's instructions immediately, as the flaw is confirmed exploited in the wild and carries a BOD 22-01 obligation for US federal agencies. As an interim measure, consider disabling the Antivirus Check Option or restricting network access to the FileZen interface, and review web/application logs for suspicious authenticated HTTP requests or unexpected command execution. Verify current FileZen versions against the vendor/JPCERT advisory to confirm you are on a fixed release. | 8.7 | 5% | KEV |
| nichelikely thousands of deployments, concentrated in Japan (no public install counts available) |
Full article352 words · extracted from helpnetsecurity.com · click to collapse
CISA has added CVE-2026-25108, an OS command injection vulnerability in Soliton Systems’ FileZen secure file transfer solution, to its Known Exploited Vulnerabilities (KEV) catalog.

The vendor has confirmed active exploitation, stating it has received multiple reports of damage caused by attackers abusing the flaw.
Because public disclosures from the Japanese CERT Coordination Center (JPCERT/CC) and a ransomware incident reported by Japan’s Washington Hotel occurred around the same time, there has been speculation that CVE-2026-25108 may have been used to deploy ransomware against organizations.
However, the KEV listing itself does not indicate that the vulnerability is currently linked to ransomware activity.
About CVE-2026-25108
The appliance-based FileZen file-sharing server is developed and sold by Tokyo-based Soliton Systems to businesses and government agencies.
The solution enables secure, authorized transfers of large files between segregated networks and provides content sanitization, antivirus scanning, and comprehensive audit logging.
CVE-2026-25108 allows remote, authenticated attackers to inject commands via a specially crafted HTTP request into a specific field on the screen after logging in (either by using compromised login credentials for a low-level account or by guessing them).
The vulnerability affects both the physical and virtual versions of FileZen, and is exploitable only if antivirus scanning is enabled. It does not affect FileZen S.
CVE-2026-25108 affects FileZen v5.0.0 to v5.0.10 and v4.2.1 to v4.2.8. Customers are urged to upgrade to v5.0.11 or later. CISA has ordered US federal civilian agencies to mitigate the vulnerability by March 17, 2026.
Japan’s CERT notes that FileZen includes a file-monitoring feature for its system directory, meaning that if those files are altered, the activity may be recorded in the logs. Customers are advised to contact the vendor for guidance on how to review and interpret those logs.
In addition, organizations should examine logs for signs of unauthorized access using compromised accounts. If evidence of such activity is identified, they should consider resetting passwords for all accounts as a precaution.
This is not the first time attackers exploited a zero-day vulnerability in FileZen.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/02/25/cve-2026-25108-filezen-vulnerability-exploited/