Exploits

CISA Adds Exploited FileZen OS Command Injection to KEV

Published  ·  3 min read

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a recently disclosed vulnerability in Soliton Systems FileZen , a file transfer solution to its Known Exploited Vulnerabilities (KEV) catalog on Tuesday, February 24, 2026, due to confirmed active exploitation in the wild. Flaw CVE-2026-25108 (CVSS Score = 8.7-High Severity) is an OS command injection vulnerability, allowing an authenticated user to execute arbitrary commands on the server by sending specially formatted HTTP request(s). To exploit this vulnerability: 1. The user must log into the web interface using valid general user credentials. 2. The FileZen Antivirus Check Option to be enabled (a common default in many deployments) According to Japan Vulnerability Notes (JVN) and Soliton’s advisory, the issue affects: 1. Versions 4.2.1 to 4.2.8 2. Versions 5.0.0 to 5.0.10 Soliton confirmed receiving at least one report of real-world damage caused by exploitation. In version 5.0.11 released (before the CISA KEV was added), the vendor has resolved the vulnerabilities and recommends 1. Immediately upgrading to at least version 5.0.10 2. Changing all user passwords to protect against possible access by an attacker if they were given valid credentials. 3. System logs should be checked for signs of compromise. Examples may include: unexpected commands, unfamiliar file transfers, or anomalous HTTP requests. CISA has established a 21-day deadline (from date of catalog addition) to remediate any applicable vulnerabilities within the Federal Civilian Executive Branch (FCEB) Agencies, as defined in BOD 22-01, to March 17, 2026. **The Importance of This Issue** File transfer appliances (known as asset transfer appliances) such as FileZen are high-value targets due to their: 1. Sensitive data transfer capabilities. 2. Positioning in either a DMZ or an internal network where all users have unrestricted access. 3. Being frequently deployed without endpoint detection and response (EDR) agents. 4. Utilizing old technology containing a common user ID and password. The hacker could use an authenticated command injection technique to acquire unauthorized access to secure information and execute bad code all over the network. This is even more true if the attacker has weak authentication methods or an open web interface. **Immediate Actions for Defenders** 1. Patch Immediately. Upgrade to FileZen Version equal or greater than 5.0.11. 2. Revoke Credentials and Passwords and Tokens. 3. Limit Access to local network Instance, No internet instances and only accessible via VPN/Jump Host. 4. Implement Multi-Factor Authentication on all accounts if available. 5. Monitoring & Search for Signs of Exploitation ; Unauthorized Commands Executed through Web Requests; Unexpected File Uploads/Downloads from Any Appliance. 6. Audit Antivirus Check ; Disable Vulnerable Functionality if Not Needed, Until Patched. This addition to CISA's KEV catalog demonstrates the continued threat of command injection through file transfer and collaboration tools, both being used extensively by cybercriminals motivated by financial gain, as well as nation-state actors wanting to gain access or maintain presence on systems. **Source:** *[The Hacker News](https://thehackernews.com/2026/02/cisa-confirms-active-exploitation-of.html)*

Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067