logo

U.S. CISA adds a flaw in Soliton Systems K.K FileZen to its Known Exploited Vulnerabilities catalog

ID: 2ba71b97-7b70-5385-b253-8bff8b107ee3

STIX ID: report--2ba71b97-7b70-5385-b253-8bff8b107ee3

Feed Name: Security Affairs

Threat Score
72/100

Date Published: 2026-02-25

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-25108—a command injection vulnerability in Soliton Systems FileZen with a CVSS v4 score of 8.7—to its Known Exploited Vulnerabilities catalog. The vulnerability permits authenticated users to execute arbitrary OS commands when the BitDefender-based virus-check feature is enabled, affects FileZen 4.2.1–4.2.8 and 5.0.0–5.0.10, and is addressed in V5.0.11; the vendor reports active exploitation and CISA requires federal remediation by March 17, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.