FileZen OS command injection exploited in wild
A high-severity OS command injection flaw in Soliton Systems' FileZen file-transfer appliance is being actively exploited, per the vendor.
IPA/JVN disclosed CVE-2026-25108, an OS command injection vulnerability affecting Soliton Systems' FileZen, a dedicated file-transfer appliance widely used in Japan. The flaw allows a logged-in user to execute arbitrary OS commands by sending a specially crafted HTTP request to the device, rated CVSS v3 8.8 (critical/high per JVN's 緊急 designation).
Affected versions span FileZen V5.0.0 through V5.0.10 and V4.2.1 through V4.2.8; FileZen S is not impacted. The vendor has confirmed that exploitation of this vulnerability has already been observed in the wild, elevating the urgency for administrators to apply the latest update immediately. No further technical details on the exploitation campaign, threat actors, or indicators were provided in the advisory.
Mentioned in this report
Source reporting: https://www.ipa.go.jp/security/security-alert/2025/20260213-jvn.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free