logo

CISA Flags Actively Exploited Wing FTP Vulnerability Leaking Server Paths

ID: bfe03500-310f-5d3c-b082-416edfebfdd0

STIX ID: report--bfe03500-310f-5d3c-b082-416edfebfdd0

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-03-17

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

CISA added CVE-2025-47813 (info disclosure, CVSS 4.3) in Wing FTP Server to its KEV list after active exploitation was observed; the bug leaked the application installation path via an overlong UID cookie and was fixed in version 7.4.4 (released alongside a patch for a separate critical RCE, CVE-2025-47812).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.