Skip to main content

Share story

Security

CISA adds CVE-2026-25108 FileZen command injection vulnerability to Known Exploited Vulnerabilities catalog

CISA adds CVE-2026-25108 FileZen command injection vulnerability to Known Exploited Vulnerabilities catalog Image: Primary
CISA has added CVE-2026-25108 to its Known Exploited Vulnerabilities catalog. The entry covers an OS command injection vulnerability in Soliton Systems FileZen secure file transfer solution. The vendor has confirmed active exploitation and stated it has received multiple reports of damage from attackers abusing the flaw. The vulnerability allows remote authenticated attackers to inject commands via a specially crafted HTTP request into a specific field after logging in. It affects both physical and virtual versions of FileZen and requires that antivirus scanning be enabled. It does not affect FileZen S. The flaw impacts FileZen v5.0.0 to v5.0.10 and v4.2.1 to v4.2.8. Customers should upgrade to v5.0.11 or later. CISA has ordered US federal civilian agencies to mitigate the vulnerability by March 17, 2026. The FileZen solution enables secure authorized transfers of large files between segregated networks. It provides content sanitization, antivirus scanning, and comprehensive audit logging. Japan CERT notes that a file-monitoring feature for the system directory may record alterations in logs. Public disclosures from the Japanese CERT Coordination Center and a ransomware incident reported by Japan Washington Hotel occurred around the same time. This timing led to speculation that the vulnerability may have been used to deploy ransomware against organizations. However the KEV listing itself does not indicate that the vulnerability is currently linked to ransomware activity.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from Help Net Security and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Science
Science

Infleqtion claims 30 entangled logical qubits on Sqale system

Infleqtion says it created 30 entangled logical qubits on its Sqale quantum computing system, a company-reported step toward operations across error-protected quantum bits. A logical qubit encodes information across multiple physi...

Capital AI
Capital AI

NUS Enterprise launches patent-matching platform and Munich outpost

NUS Enterprise says it has launched Nova, an AI platform developed with Zima Labs to help its staff find commercial partners for university research. It has also established an outpost in Munich through a partnership with Unterneh...

Security
Security

NFM Lending faces lawsuit after acknowledged cyber incident

NFM Lending faces a class-action lawsuit after acknowledging a cybersecurity incident, The Tech Edvocate reports. Former customer Sheneka Smith alleges that the mortgage lender failed to maintain reasonable safeguards for customer...

AI Capital
AI Capital

Chinese local governments offer incentives to AI filmmakers

Reuters reports that Chinese local governments are offering computing vouchers, rent waivers and dedicated funding to attract filmmakers using artificial intelligence. These incentives reduce the cost of computing and premises for...

Security AI
Security AI

GitHub Security Lab releases agent workflow for automated fuzz testing

GitHub Security Lab has published a workflow that uses an AI agent to set up and run fuzz tests for C and C++ projects. Given a repository, it selects functions to test, writes test harnesses, runs AFL++, checks which code the tes...