logo

Exploited Wing file transfer bug risks ‘total server compromise,’ CISA warns

ID: 554a9157-173a-5845-8d95-59a9f60804ed

STIX ID: report--554a9157-173a-5845-8d95-59a9f60804ed

Feed Name: The Record from Recorded Future News

Threat Score
90/100

Date Published: 2025-07-14

Date Updated: 2026-05-01

...
...

**Executive summary:** A critical remote code execution flaw (CVE-2025-47812) in Wing FTP Server — rated 10/10 and described as allowing total server compromise — is being actively exploited; CISA added it to the Known Exploited Vulnerabilities catalog and ordered urgent patching. Security firms observed exploitation attempts, post-exploitation activity (downloads, reconnaissance, remote monitoring software installs), and internet-wide scans show thousands of exposed instances, so organizations should update to Wing FTP Server 7.4.4 immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.