CVE-2026-25108: Soliton Systems K.K FileZen OS Command Injection Vulnerability

High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2026-02-24. EPSS: 5.2% chance of exploitation in the next 30 days.

FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user may send a specially crafted HTTP request to execute an arbitrary OS command.

Affected products

  • Soliton FileZen: from 4.2.1, before 5.0.11 (fixed in 5.0.11)

Published 2026-02-13. Last modified 2026-06-17.