logo

CISA Confirms Active Exploitation of FileZen CVE-2026-25108 Vulnerability

ID: 30761b79-ba3d-5cdc-8d69-e4b1f903533f

STIX ID: report--30761b79-ba3d-5cdc-8d69-e4b1f903533f

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-02-25

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

CISA has added CVE-2026-25108 — an OS command injection vulnerability in Soliton Systems' FileZen (CVSS v4 8.7) — to its Known Exploited Vulnerabilities catalog after evidence of active exploitation and at least one reported instance of damage; the flaw affects FileZen versions 4.2.1–4.2.8 and 5.0.0–5.0.10, requires an authenticated user with the Antivirus Check Option enabled, and Soliton advises updating to v5.0.11 or later (FCEB agencies must patch by March 17, 2026).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.