The US Cybersecurity and Infrastructure Security Agency (CISA) has added a FileZen vulnerability to its List of Known Exploitable Vulnerabilities (KEV) , confirming that there is evidence of active exploitation.

This move signals an increased level of risk for organizations using this particular file transfer software, as the KEV list only includes security vulnerabilities that have already been exploited by attackers.
The vulnerability is identified as CVE-2026-25108 and has received a CVSS v4 score of 8.7 /10, which makes it a critical threat for enterprise environments. It is an OS command injection vulnerability , allowing an authenticated user to execute arbitrary commands via specially crafted HTTP requests.
What is CVE-2026-25108 and how does the attack work?
According to the official CISA position, the FileZen from Soliton Systems KK has a security vulnerability when a user logs in to the system and sends a modified HTTP request. If the attack is successful, the attacker may gain the ability to execute commands on the operating system.
See also: VMware fixes vulnerability in Aria Operations
This form of attack is particularly dangerous, as it can lead to complete control of the affected system, data extraction , or malware installation. In environments where FileZen is used to manage and transfer sensitive files, the consequences can be severe.

Which versions are affected?
According to the Japan Vulnerability Notes (JVN), the issue affects the following versions of FileZen:
- Versions 4.2.1 to 4.2.8
- Versions 5.0.0 to 5.0.10
Soliton clarified that successful exploitation is only possible when the FileZen Antivirus Check Option. However, the company revealed that it has already received at least one report of actual damage attributed to the exploitation of the vulnerability, which confirms that the flaw is not theoretical.
Additionally, the attack requires the malicious user to be logged in with general user rights to the web interface. This means that the threat mainly concerns scenarios where credentials have been leaked or where there is an insider risk.
Mitigation guidelines and compliance deadlines
Soliton recommends immediately upgrading to version 5.0.11 or later, where the issue has been fixed. In addition, in cases where a breach is suspected, the company recommends changing all user passwords, as an attacker may have gained access to a valid account.
CISA, following its usual practice, has set a specific deadline for federal agencies. Federal Civilian Executive Branch (FCEB) agencies are asked to apply the necessary patches by March 17, 2026 , ensuring that their networks are not left exposed.
See also: Microsoft fixes serious vulnerability in Windows Admin Center

A vulnerability being listed on the KEV list is not just a recommendation; it serves as a clear warning that the threat is active and imminent. For federal agencies, compliance is mandatory, while for the private sector, rapid response is strongly recommended.
The broader context: File management and cyberattacks
File management and transfer systems have long been attractive targets for attackers, as they often act as central hubs for exchanging sensitive data. In recent years, incidents of exploiting vulnerabilities in file transfer platforms have led to massive leaks and ransomware campaigns.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: SolarWinds Serv-U: Critical vulnerabilities allow root access
The FileZen case highlights the need for a multi-layered defense: strict permissions management, active log monitoring, periodic security audits , and prompt application of updates. At the same time, the requirement for user authentication and credential protection becomes critical, given that this vulnerability requires a login to the system.
As attacks become more targeted and exploit legitimate accounts, the line between external and internal threats is blurring. The addition of CVE-2026-25108 to the KEV list is another wake-up call for organizations managing critical infrastructure: early notification and proactive security is not an option, but a business necessity.
