LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-47813: Wing FTP Server Information Disclosure Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 16, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 30, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-47813 to its Known Exploited Vulnerabilities catalog on Mar 16, 2026, with a federal patch deadline of Mar 30, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Wing FTP Server contains a generation of error message containing sensitive information vulnerability when using a long value in the UID cookie.

Wing FTP Server contains an information disclosure vulnerability, CVE-2025-47813. The flaw belongs to the class of issues where error messages expose sensitive information. It is triggered when the server processes a long value supplied in the UID cookie. This matters for organizations that rely on Wing FTP Server for file transfers, as unintended data leakage can occur during normal error handling.

How it works

The weakness is categorized as CWE-209, generation of error message containing sensitive information. In this product class an attacker supplies an unusually long UID cookie value. The server responds with an error that includes internal details not intended for disclosure.

Technical readers should note that the trigger is tied specifically to cookie handling rather than authentication bypass or command execution. Exact reproduction steps and affected configurations must be confirmed against the vendor advisory.

Am I affected? How to find it in your systems

Wing FTP Server instances are typically deployed on Windows or Linux hosts that accept inbound FTP, FTPS, or HTTP-based management connections. Begin by inventorying all servers running this software through asset management tools, service discovery scans, or configuration management databases.

How to remediate

Apply mitigations per vendor instructions as the primary step. Where the advisory identifies an update, install it on all affected instances before re-enabling external access.

If you can't patch immediately

Until a fix is in place, apply compensating controls that reduce exposure of the affected component. Segment Wing FTP Server hosts so that only trusted networks can reach management or file transfer ports.

If your data may have been exposed

Actively exploited vulnerabilities lead to breaches. You can run a free exposure scan of your email addresses to check known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedWing FTP Server · Wing FTP Server
WeaknessCWE-209
Added to CISA KEVMar 16, 2026
Federal patch deadlineMar 30, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities