CVE-2026-25108Active Exploitation(soliton / filezen)

HIGHCVSS 8.8 · HIGHCISA KEV

Exploitation observed; activity peaked at 56 mentions and remains active

Immediate actions

  • Patch soliton filezen systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user may send a specially crafted HTTP request to execute an arbitrary OS command.

6.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-03-17. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-78

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • filezen

Threat summary

  • Active exploitation appears in 94 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 110 mentions across 18 observed days

What's happening

  • Active exploitation reported across 94 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 37 signals
  • Technical details provided in 65 signals
  • Disclosure: 6 classified signals
  • Peaked 12d ago at 56 mentions (2026-02-25); latest day: 2
  • 110 total mentions across 18 days

Affected systems

Vendors
Products
filezen

Deep dive

Activity timeline110 mentions / 18d
014284256Mentions · 2026-02-13: 7Mentions · 2026-02-15: 1Mentions · 2026-02-16: 8Mentions · 2026-02-17: 4Mentions · 2026-02-24: 3Mentions · 2026-02-25: 56Mentions · 2026-02-26: 16Mentions · 2026-02-27: 3Mentions · 2026-02-28: 2Mentions · 2026-03-01: 1Mentions · 2026-03-02: 1Mentions · 2026-03-03: 1Mentions · 2026-03-04: 1Mentions · 2026-03-26: 1Mentions · 2026-04-11: 1Mentions · 2026-04-15: 1Mentions · 2026-05-05: 1Mentions · 2026-05-08: 2PoC Mentioned / Linked · 2026-05-08: 1Active Exploitation · 2026-02-13: 3Active Exploitation · 2026-02-16: 6Active Exploitation · 2026-02-17: 3Active Exploitation · 2026-02-24: 3Active Exploitation · 2026-02-25: 55Active Exploitation · 2026-02-26: 14Active Exploitation · 2026-02-27: 2Active Exploitation · 2026-02-28: 1Active Exploitation · 2026-03-01: 1Active Exploitation · 2026-03-03: 1Active Exploitation · 2026-03-04: 1Active Exploitation · 2026-03-26: 1Active Exploitation · 2026-04-11: 1Active Exploitation · 2026-04-15: 1Active Exploitation · 2026-05-08: 1Patch / Workaround · 2026-02-13: 1Patch / Workaround · 2026-02-15: 1Patch / Workaround · 2026-02-16: 3Patch / Workaround · 2026-02-17: 2Patch / Workaround · 2026-02-25: 18Patch / Workaround · 2026-02-26: 7Patch / Workaround · 2026-02-27: 2Patch / Workaround · 2026-03-01: 1Patch / Workaround · 2026-03-02: 1Patch / Workaround · 2026-04-15: 1Technical Details · 2026-02-13: 7Technical Details · 2026-02-15: 1Technical Details · 2026-02-16: 8Technical Details · 2026-02-17: 4Technical Details · 2026-02-24: 3Technical Details · 2026-02-25: 27Technical Details · 2026-02-26: 6Technical Details · 2026-02-27: 2Technical Details · 2026-03-01: 1Technical Details · 2026-03-02: 1Technical Details · 2026-03-03: 1Technical Details · 2026-03-04: 1Technical Details · 2026-04-11: 1Technical Details · 2026-05-05: 1Technical Details · 2026-05-08: 102-1302-1502-1602-1702-2402-2502-2602-2702-2803-0103-0203-0303-0403-2604-1104-1505-0505-08
Signal classification4 categories
Active Exploitation
9485.5%
Disclosure
65.5%
Patch
54.5%
General
54.5%
Referenced assets87 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-137
Active Exploitation3Disclosure3Patch1
2026-02-151
Patch1
2026-02-168
Active Exploitation6Disclosure2
2026-02-174
Active Exploitation3Patch1
2026-02-243
Active Exploitation3
2026-02-2556
Active Exploitation55General1
2026-02-2616
Active Exploitation14General2
2026-02-273
Active Exploitation2Patch1
2026-02-282
Active Exploitation1General1
2026-03-011
Active Exploitation1
2026-03-021
Patch1
2026-03-031
Active Exploitation1
2026-03-041
Active Exploitation1
2026-03-261
Active Exploitation1
2026-04-111
Active Exploitation1
2026-04-151
Active Exploitation1
2026-05-051
General1
2026-05-082
Active Exploitation1Disclosure1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Active Exploitation

    🚨 CISA added CVE-2026-25108 to its KEV list after active exploitation. The FileZen bug allows an authenticated user to execute OS commands via crafted HTTP requests. Impacts versions 4.2.1–4.2.8 and 5.0.0–5.0.10 when Antivirus Check is enabled. At least one incident confirmed. 🔗 Read → https://thehackernews.com/2026/02/cisa-confirms-active-exploitation-of.html

    Post summary

    CISA confirmed active exploitation of CVE-2026-25108, enabling authenticated users to execute OS commands via crafted HTTP requests in FileZen versions 4.2.1–4.2.8 and 5.0.0–5.0.10.

    32115068.5K
    1.0M followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️ We added Soliton Systems K.K. FileZen OS command injection vulnerability CVE-2026-25108 to our Known Exploited Vulnerabilities Catalog. Visit https://go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/5cuQVm74vy

    Post summary

    The tweet announces that CVE-2026-25108, a command injection flaw in Soliton Systems FileZen OS, is listed as a known exploited vulnerability and urges organizations to apply mitigations.

    3801834.3K
    291.9K followersView on X
  • JPCERTコーディネーションセンター@jpcert
    Active Exploitation

    FileZenにおけるOSコマンドインジェクションの脆弱性(CVE-2026-25108)に関する注意喚起を公開。すでに脆弱性の悪用が確認されています。開発者が提供する最新の情報をもとに、対策や侵害有無の調査の実施を検討してください。^KK https://www.jpcert.or.jp/at/2026/at260004.html

    Post summary

    The advisory warns that CVE-2026-25108, an OS command injection in FileZen, has already been exploited. Organizations should investigate incidents and apply recommended mitigations.

    01101634.5K
    33.1K followersView on X
  • Dark Web Informer@DarkWebInformer
    Active Exploitation

    ‼️CISA has added one vulnerability to the KEV Catalog CVE-2026-25108: Soliton Systems K.K FileZen OS Command Injection Vulnerability: Soliton Systems K.K FileZen contains an OS command injection vulnerability when an user logs-in to the affected product and sends a specially crafted HTTP request.

    Post summary

    CISA has listed CVE-2026-25108 in its KEV catalog, indicating it is being actively exploited in the wild; the vulnerability is an OS command injection in Soliton FileZen triggered by a crafted HTTP request.

    0501633.9K
    166.2K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(2/24追加) 🛡️No.1528 CVE-2026-25108 Soliton Systems K.K. FileZen OS Command Injection Vulnerability ============= CVSSスコア: 8.7 (Base) / JPCERT/CC CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N 種別:OSコマンドインジェクション (CWE-78 / JPCERT/CC) 深刻度:重要 ---------------------- 悪用時影響: 認証済みの攻撃者により、特別に細工された HTTP リクエストを送信されることで、OSコマンドを実行される恐れがあります。 https://jvn.jp/en/jp/JVN84622767/ CISA Adds One Known Exploited Vulnerability to Catalog | CISA https://www.cisa.gov/news-events/alerts/2026/02/24/cisa-adds-one-known-exploited-vulnerability-catalog #vulnerability

    Post summary

    CISA confirmed that CVE-2026-25108 is actively exploited in the wild, with OS command injection details and severity provided, but no PoC or patch information is included.

    0201206.5K
    42.6K followersView on X
  • Blue Team News@blueteamsec1
    Active Exploitation

    CISA Confirms Active Exploitation of FileZen CVE-2026-25108 Vulnerability http://dlvr.it/TRk0Jk #Cybersecurity #Vulnerability #CISA #FileZen #CVE202625108 https://t.co/yAAE5eSpVx

    Post summary

    CISA confirms that FileZen CVE-2026-25108 is currently being actively exploited in the wild, but no PoC or patch details are provided.

    02070814
    55.2K followersView on X
  • Nicolas Krassas@Dinosn
    Active Exploitation

    CISA Confirms Active Exploitation of FileZen CVE-2026-25108 Vulnerability https://thehackernews.com/2026/02/cisa-confirms-active-exploitation-of.html

    Post summary

    CISA confirms that CVE-2026-25108 in FileZen is actively exploited in the wild.

    120421.1K
    151.6K followersView on X
  • Autumn Good@autumn_good_35
    Active Exploitation

    🚨🚨🚨 『株式会社ソリトンシステムズは、本脆弱性の悪用を確認しているとのことです』 2026-02-13 JPCERT/CC FileZenにおけるOSコマンドインジェクションの脆弱性(CVE-2026-25108)に関する注意喚起 https://www.jpcert.or.jp/at/2026/at260004.html

    Post summary

    JPCERT/CC notes that Soliton Systems has confirmed exploitation of the OS command injection CVE-2026-25108 in FileZen, with no patch or PoC disclosed.

    03022821
    6.7K followersView on X
  • The Cyber Security Hub™@TheCyberSecHub
    Active Exploitation

    CISA flags exploited FileZen command injection bug, patch now! (CVE-2026-25108) https://www.helpnetsecurity.com/2026/02/25/cve-2026-25108-filezen-vulnerability-exploited/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    CISA reports that CVE-2026-25108, a command injection flaw in FileZen, is actively being exploited, and a patch is now available.

    12030461
    193.3K followersView on X
  • Dr.Mashari@GMashari
    Active Exploitation

    📌 ثغرة في تطبيق نقل الملفات FileZen تتيح تنفيذ أوامر برمجية عشوائية 🛡️ الفئة: ثغرة 📝 الملخص: تم اكتشاف ثغرة أمنية حرجة في حل نقل الملفات FileZen التابع لشركة Soliton Systems، تحمل المعرف CVE-2026-25108 وبدرجة خطورة 8.8 وفق مقياس CVSS. تنشأ الثغرة من خلل في حقن أوامر نظام التشغيل (OS Command Injection) يظهر عند تفعيل خيار فحص الفيروسات، مما يسمح للمهاجمين الموثقين بتنفيذ أوامر برمجية بصلاحيات مرتفعة عبر طلبات HTTP مصممة خصيصاً. أكد المطورون رصد محاولات استغلال فعلية لهذه الثغرة في بيئات العمل، مما يهدد سلامة الأنظمة والبيانات الحساسة داخل الشبكات المؤسسية. يُنصح بـ ترقية الأنظمة المتأثرة إلى الإصدار V5.0.11 أو أحدث فوراً لسد هذه الفجوة الأمنية ومنع الوصول غير المصرح به. 📍 تفاصيل فنية: 🎯 الهدف: أنظمة نقل الملفات FileZen في بيئات الشركات والشبكات الداخلية. 🧠 التقنية المستخدمة: حقن أوامر نظام التشغيل (CWE-78) عبر طلبات HTTP معيبة تستهدف آلية المعالجة. 🚨 الإجراء المتخذ: أصدرت Soliton Systems تحديثاً للبرامج الثابتة (Firmware) لمعالجة ثغرة تنفيذ الأوامر. 🛑 التوصيات الأمنية: التحديث الفوري لإصدار V5.0.11 وتدقيق سجلات الوصول للبحث عن مؤشرات استغلال سابقة. 🗓️ تاريخ النشر: 16/02/2026 🔗 للمزيد: https://cybersecuritynews.com/filezen-file-transfer-app-vulnerability/

    Post summary

    CVE‑2026‑25108 is a critical OS command injection in FileZen that has been actively exploited in corporate environments; immediate patching to V5.0.11 is required.

    02030121
    9.2K followersView on X
  • にゃん☆たく/takumi.a@taku888infinity
    Active Exploitation

    FileZenにおけるOSコマンドインジェクションの脆弱性(CVE-2026-25108)に関する注意喚起 https://www.jpcert.or.jp/at/2026/at260004.html 『株式会社ソリトンシステムズがFileZenにおけるOSコマンドインジェクションの脆弱性(CVE-2026-25108)に関する情報を公表しました。本脆弱性を悪用されると、当該製品にログオンしたユーザーが、任意のOSコマンドを実行する可能性があります。株式会社ソリトンシステムズは、本脆弱性の悪用を確認しているとのことです。』

    Post summary

    CVE‑2026‑25108 is an OS command injection flaw in FileZen that is confirmed to be exploited in the wild, yet no patch or exploit code details are provided.

    000411.4K
    11.3K followersView on X
  • Gray Hats@the_yellow_fall
    Active Exploitation

    Critical FileZen flaw CVE-2026-25108 is under active attack. Antivirus feature allows command injection. Update to V5.0.11 immediately to secure data. #FileZen #CyberSecurity #CVE202625108 #InfoSec #ZeroDay #PatchNow https://securityonline.info/jpcert-cc-warns-of-active-exploits-targeting-critical-filezen-command-injection-flaw/

    Post summary

    CVE-2026-25108 is a command‑injection vulnerability in FileZen that is currently being actively exploited; users should immediately update to V5.0.11 to mitigate the threat.

    00012343
    10.3K followersView on X
  • Mitsuru SHIMAMURA@smbd
    General

    FileZenにおけるOSコマンドインジェクションの脆弱性(CVE-2026-25108)に関する注意喚起 https://www.jpcert.or.jp/at/2026/at260004.html 2026-02-13

    Post summary

    The advisory notes a new CVE-2026-25108 OS command injection flaw in FileZen but does not provide details about PoCs, exploits, active attacks, or mitigation, making it a general notification.

    01010486
    1.2K followersView on X
  • Visium Technologies, Inc.@VisiumAnalytics
    Active Exploitation

    $VISM 🚨 CISA just added another critical OS command injection (CVE-2026-25108) to its KEV catalog, actively exploited! 🤯 This isn't just news; it's a stark reminder of the constant threat landscape. How do you stay ahead? Visium's #TruContext agentic AI platform autonomously detects & neutralizes emerging threats like these, turning reactive defense into proactive resilience. Don't just react, anticipate. Learn more about the threat: https://thehackernews.com/2026/02/cisa-confirms-active-exploitation-of.html #Cybersecurity #CISA #KEV #AI #AgenticAI #ThreatIntelligence #OSCommandInjection #TruContext

    Post summary

    CISA confirms that CVE-2026-25108, an OS command injection vulnerability, is actively exploited in the wild, underscoring the urgency for defensive action.

    0101088
    5.9K followersView on X
  • Red Secure Tech Ltd.@redsecuretech
    Active Exploitation

    CISA adds CVE-2026-25108 (CVSS 8.7) in Soliton FileZen to Known Exploited Vulnerabilities catalog due to active exploitation. https://www.redsecuretech.co.uk/blog/post/cisa-adds-exploited-filezen-os-command-injection-to-kev/982 #Cybersecurity #CISA #FileZen #CVE #RCE #KEV #ThreatIntel #Vulnerability #PatchNow https://t.co/e9dtvv5ni9

    Post summary

    CISA has added CVE-2026-25108 to its Known Exploited Vulnerabilities catalog, indicating active exploitation of an OS command injection flaw in Soliton FileZen.

    0101054
    42 followersView on X
  • CTIWatch@ctiwatchcloud
    Active Exploitation

    🚨 [HIGH] Active exploitation detected: CVE-2026-25108 Exploit in the wild confirmed for CVE-2026-25108 (CVSS 8.8). FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Opti... 🔗 http://ctiwatch.cloud/alerts #ZeroDay #ExploitInWild #CyberSecurity

    Post summary

    CVE-2026-25108, an OS command injection flaw in FileZen with a CVSS score of 8.8, is actively exploited in the wild according to the alert.

    00010114
    5.6K followersView on X
  • iototsecnews@iototsecnews
    Active Exploitation

    CISA KEV 警告 26/02/24:FileZen の脆弱性 CVE-2026-25108 を登録 https://iototsecnews.jp/2026/02/25/cisa-issues-alert-on-active-exploitation-of-filezen-vulnerability/ 日本の Soliton Systems が開発するファイル共有ソリューション FileZen に、OS コマンド・インジェクションの脆弱性 CVE-2026-25108 が発見され、米国の CISA によりKEV カタログに登録されました。この脆弱性は、システムが外部からの入力を適切に処理せず、そのままオペレーティングシステムへの命令として実行してしまうという不備に起因します。 攻撃者は、Webインターフェイスなどを通じて特定の入力を送り込むだけで、管理者権限で任意のコマンドを実行できるため、データの窃取やネットワーク内へのさらなる侵入といった、組織の根幹を揺るがす被害に直結する恐れがあります。 #CVE202625108 #FileZen #Government #Vulnerability

    Post summary

    CISA has listed CVE-2026-25108 for FileZen as a known exploited vulnerability, describing an OS command injection that allows attackers to run arbitrary commands with admin privileges.

    01000136
    483 followersView on X
  • Mr.Rabbit@01ra66it
    Patch

    FileZenファイル共有サーバにコマンドインジェクション脆弱性。 認証済アカウント悪用でリモートコマンド実行が可能。 ログ監査とパッチ適用が強く推奨。 https://www.helpnetsecurity.com/2026/02/25/cve-2026-25108-filezen-vulnerability-exploited/

    Post summary

    FileZen file sharing server suffers from a command injection vulnerability that permits remote command execution through authenticated accounts; patching is strongly recommended.

    00001297
    3.3K followersView on X
  • i2develop@i2develop1
    Active Exploitation

    🚨 Soliton FileZen (CVE-2026-25108) is under active attack. Hackers are using command injection to jump between 'secure' network segments. If you use FileZen with AV enabled, patch to v5.0.11 NOW. Don't let a file transfer be your downfall! #CISA #InfoSec #CyberSecurity https://t.co/ozIaT9hyo0

    Post summary

    The tweet reports that Soliton FileZen CVE‑2026‑25108 is being actively exploited via command injection and advises users to patch to v5.0.11 immediately.

    0001092
    107 followersView on X
  • transilienceai@transilienceai
    General

    🚨 FileZen [Critical] Feb 28, 2026 Product Security Advisory Report for FileZen Vulnerability (CVE-2026-25108) Checkout our Threat Intelligence Platform: https://threatintel.transilience.cloud https://threatintel.transilience.cloud #ThreatIntelligence #CyberSecurity #Innovation https://t.co/dXkEvaJRIy

    Post summary

    The tweet announces a critical CVE for FileZen but gives no technical, exploit, or mitigation details.

    1000044
    319 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsolitonfilezen---

Explore more