Monday, September 7, 2026

CISA Issues Alert on Active Exploitation of FileZen Vulnerability

The Cybersecurity and Infrastructure Security Agency (CISA) has added a new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, citing evidence of active exploitation in the wild.

The vulnerability affects FileZen, a file-sharing and data transfer product developed by Japanese vendor Soliton Systems K.K.

The flaw, tracked as CVE-2026-25108, is classified as an OS Command Injection vulnerability.

This type of weakness allows attackers to inject and execute arbitrary operating system commands on a target system, potentially leading to full system compromise.

OS command injection vulnerabilities are considered high-severity threats and are frequently abused by malicious cyber actors as initial access vectors into enterprise networks.

CVE IDCVSS ScoreDescription
CVE-2026-25108N/ASoliton Systems K.K. FileZen OS Command Injection Vulnerability

CISA’s KEV Catalogue mandates that all Federal Civilian Executive Branch (FCEB) agencies remediate listed vulnerabilities within a designated timeframe.

The directive was established to reduce the significant risk posed by known exploited vulnerabilities across federal networks.

Agencies that fail to patch within the required window remain exposed to active threat actors targeting these exact weaknesses.

While BOD 22-01 is binding only for federal agencies, CISA strongly urges all private and public sector organizations to treat KEV Catalog entries as high-priority remediation targets.

Timely patching of actively exploited vulnerabilities remains one of the most effective defenses against cyberattacks.

Organisations using FileZen should immediately review CISA’s KEV Catalogue for remediation deadlines and apply available patches or mitigations from Soliton Systems K.K. Security teams should also audit systems for signs of compromise, particularly any unauthorised command execution activity.

Incorporating KEV Catalog entries into routine vulnerability management workflows is strongly recommended.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

PoisonedRefresh Malware Backdoors F5 BIG-IP Servers With Memory-Only PHP Web Shells

A sophisticated Linux implant linked to compromised F5 BIG-IP...

Natural Resources Wales Data Breach Exposes Sensitive Employee Diversity Data

Natural Resources Wales (NRW) has reported a personal data...

ConnectWise ScreenConnect Remote Access Flaw Impacts Guest File Transfer Sessions

ConnectWise has announced a security issue affecting file transfer...

Global Phishing Campaign Abuses Google Infrastructure to Evade Security and Steal Credentials

A large-scale phishing operation is abusing trusted Google services...

OpenAI Commits $1 Billion in Daybreak AI Cyber Tools to Protect Critical Infrastructure

OpenAI has announced a $1 billion global commitment to...

Tengu Mirai-Style Linux Bot Hides as Kernel Worker to Launch DDoS and Proxy Attacks

A newly analyzed Linux malware sample, dubbed Tengu, combines...

The 12 Best Wireless / Wi-Fi Security Solutions, Compared and Priced

Best value overall: Ubiquiti. Published hardware pricing, no mandatory...

The 12 Best Network Sandboxing Solutions, Compared and Priced

Best value overall: ANY.RUN. It publishes its pricing, offers...

Related Articles

Recent News