LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-25108: Soliton Systems K.K FileZen OS Command Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 24, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 17, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-25108 to its Known Exploited Vulnerabilities catalog on Feb 24, 2026, with a federal patch deadline of Mar 17, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Soliton Systems K.K FileZen contains an OS command injection vulnerability when an user logs-in to the affected product and sends a specially crafted HTTP request.

This vulnerability affects Soliton Systems K.K FileZen and allows an authenticated user to trigger operating system command execution by sending a specially crafted HTTP request after login. The issue stems from insufficient validation of input that reaches system command execution paths, which can give an attacker a foothold inside the environment that hosts the product.

How it works

The weakness is classified as CWE-78, improper neutralization of special elements used in an OS command. After successful authentication, an attacker supplies crafted data inside an HTTP request that the application passes to an underlying operating system command without adequate escaping or filtering.

Am I affected? How to find it in your systems

FileZen is a file-transfer and management product that may be deployed on premises or as a cloud service. Begin by inventorying all instances through configuration management databases, network scans for known service ports, or application directories that contain FileZen binaries and configuration files.

How to remediate

Apply the mitigations or update supplied by the vendor as the primary action. The advisory is the authoritative source for the exact remediation steps and any required configuration changes.

If you can't patch immediately

Until the vendor fix can be applied, reduce exposure through network segmentation that limits inbound access to FileZen instances to only trusted administrative networks. Consider virtual patching or request filtering at a web application firewall layer for the affected endpoints, and monitor logs for anomalous authenticated HTTP traffic. If mitigations cannot be implemented, discontinue use of the product as stated in the CISA guidance.

If your data may have been exposed

Actively exploited command-injection vulnerabilities have led to unauthorized access and data exposure in other products. Organizations can run a free exposure scan of their email addresses against known breach data to check for prior incidents involving their domains.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSoliton Systems K.K · FileZen
WeaknessCWE-78
Added to CISA KEVFeb 24, 2026
Federal patch deadlineMar 17, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities