CISA added CVE-2026-25108, an OS command injection vulnerability in Soliton Systems K.K. FileZen, to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. The issue can be triggered after an authenticated user logs in and sends a specially crafted HTTP request, enabling command injection (CWE-78) and creating a high-risk pathway for follow-on compromise.
Under Binding Operational Directive (BOD) 22-01, U.S. Federal Civilian Executive Branch (FCEB) agencies are required to remediate KEV-listed vulnerabilities by the specified due date (set to 2026-03-17 for this entry) or take other risk-reducing actions per vendor guidance, including discontinuing use if mitigations are unavailable. CISA also urged non-federal organizations to prioritize remediation of KEV items as part of routine vulnerability management due to their demonstrated exploitation in the wild.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
CISA added Soliton FileZen vulnerability CVE-2026-25108 to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation. Under BOD 22-01, CISA directed U.S. federal civilian agencies to remediate the issue by March 17, 2026, and urged all organizations to prioritize patching.
In its disclosure, Soliton said it had confirmed active exploitation of CVE-2026-25108 and reported at least one instance of damage, with some reports describing multiple damage reports. The company also noted exploitation requires valid user access to the web interface.
Soliton Systems K.K. disclosed CVE-2026-25108, an authenticated OS command injection vulnerability in FileZen affecting versions 4.2.1–4.2.8 and 5.0.0–5.0.10 when the antivirus check feature is enabled. The vendor advised customers to upgrade to FileZen 5.0.11 or later and consider changing all user passwords as a precaution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
7 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecybersecuritynews.com
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourcehelpnetsecurity.com
Open sourcegithub.com
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.