CISA added Wing FTP Server vulnerability CVE-2025-47813 to its Known Exploited Vulnerabilities (KEV) catalog, warning that the flaw is being actively exploited and requiring Federal Civilian Executive Branch agencies to remediate it by March 30, 2026 under BOD 22-01. The issue affects Wing FTP Server versions prior to 7.4.4 and stems from improper handling of an overly long UID cookie in loginok.html, which can cause the server to disclose the application's full local installation path during web authentication.
Although CVE-2025-47813 is an information disclosure issue rather than a standalone remote code execution bug, reporting indicates it can support attacker reconnaissance and may be chained with other Wing FTP Server flaws in broader attack paths. The vendor patched the vulnerability in May 2025 in version 7.4.4, alongside CVE-2025-47812 and CVE-2025-27889, and researcher Julien Ahrens previously published proof-of-concept details showing how the path disclosure could aid exploitation. Organizations using Wing FTP Server, not just federal agencies, should verify they are no longer running vulnerable versions and review exposure of web-based authentication components.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
Under Binding Operational Directive 22-01, CISA required Federal Civilian Executive Branch agencies to patch or mitigate affected Wing FTP Server systems by 2026-03-30. CISA also urged private-sector organizations to prioritize remediation or stop using affected instances until mitigations are in place.
On 2026-03-16, CISA added Wing FTP Server flaw CVE-2025-47813 to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation. The bug affects versions before 7.4.4 and can expose the application's full local installation path via a long UID cookie during web authentication.
By March 2026, attackers were observed exploiting CVE-2025-47813 in real-world attacks. Reporting cited use of the flaw for reconnaissance, downloading and executing malicious Lua files, and installing remote monitoring and management software.
In June 2025, security researcher Julien Ahrens published proof-of-concept code for CVE-2025-47813. He said the path disclosure flaw could be used in the same exploit chain as CVE-2025-47812.
In May 2025, Wing FTP Server released version 7.4.4 to fix CVE-2025-47813, CVE-2025-47812, and CVE-2025-27889. The fixes addressed an installation-path disclosure bug, a critical remote code execution flaw, and an information disclosure issue that could expose user passwords.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourcesecurityaffairs.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.