# FileZen OS command injection exploited in wild

Published: 2026-02-12 · Severity: high · Sectors: technology
Canonical: https://vorant.io/reports/953c1cc4-70aa-57da-b07b-453a51494f5f/filezen-os-command-injection-exploited-in-wild

> A high-severity OS command injection flaw in Soliton Systems' FileZen file-transfer appliance is being actively exploited, per the vendor.

IPA/JVN disclosed CVE-2026-25108, an OS command injection vulnerability affecting Soliton Systems' FileZen, a dedicated file-transfer appliance widely used in Japan. The flaw allows a logged-in user to execute arbitrary OS commands by sending a specially crafted HTTP request to the device, rated CVSS v3 8.8 (critical/high per JVN's 緊急 designation).

Affected versions span FileZen V5.0.0 through V5.0.10 and V4.2.1 through V4.2.8; FileZen S is not impacted. The vendor has confirmed that exploitation of this vulnerability has already been observed in the wild, elevating the urgency for administrators to apply the latest update immediately. No further technical details on the exploitation campaign, threat actors, or indicators were provided in the advisory.

## Mentioned in this report

- Vulnerabilities: CVE-2026-25108 (KEV)

Source reporting: https://www.ipa.go.jp/security/security-alert/2025/20260213-jvn.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/953c1cc4-70aa-57da-b07b-453a51494f5f/filezen-os-command-injection-exploited-in-wild.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
