Threat reportVulnerabilityTL-2026-0169

CVE-2026-25108 Soliton FileZen OS Command Injection — CISA KEV Active Exploitation of Japan-Market File Transfer Appliance

criticalPATCHED

CVE-2026-25108 Soliton FileZen OS Command Injection (TL-2026-0169), also tracked as JVN#84622767, is a critical-severity software vulnerability scored CVSS 8.8, first published 2026-03-02. It has no confirmed attribution, affects Soliton Systems FileZen, references 1 CVE (CVE-2026-25108), maps to 14 MITRE ATT&CK techniques (T1059.004, T1068, T1070.004), and is covered by 9 detection rules and 16 indicators of compromise.

CVSS
8.8/10Critical
CVEs
1Referenced vulnerabilities
Techniques
14MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
16Indicators of compromise

Key facts for TL-2026-0169

Threat ID
TL-2026-0169
Also known as
JVN#84622767, JPCERT-AT-2026-0004, JVNDB-2026-000023
Severity
CRITICAL
CVSS
8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Status
PATCHED
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
government, financial, enterprise, healthcare, education, critical-infrastructure
Target regions
Japan, East Asia
Detection rules
9
Indicators of compromise
16

How CVE-2026-25108 Soliton FileZen OS Command Injection works

Soliton Systems FileZen, a file sharing and transfer appliance widely deployed in Japanese government and enterprise environments, contains an OS command injection vulnerability (CVE-2026-25108, CVSS 8.8) that is being actively exploited in the wild. CISA added this to the KEV catalog on 2026-02-24 with an emergency remediation deadline of 2026-03-17.

CVE-2026-25108 is an OS command injection vulnerability (CWE-78) in Soliton Systems FileZen, a file sharing and transfer appliance predominantly deployed across Japanese government agencies, financial institutions, and enterprise environments. The vulnerability affects FileZen versions V4.2.1 through V4.2.8 and V5.0.0 through V5.0.10, and was patched in V5.0.11 released on January 13, 2026.

The vulnerability exists in the post-authentication web interface and can be exploited when the FileZen Antivirus Check Option (powered by BitDefender) is enabled. An authenticated user can send specially crafted HTTP requests to inject arbitrary OS commands that execute on the underlying operating system with the privileges of the FileZen service. This means exploitation requires two preconditions: (1) the BitDefender antivirus check option must be active, and (2) the attacker must possess valid credentials for at least one user account.

Soliton Systems coordinated disclosure with JPCERT/CC, publishing JVN#84622767 on February 13, 2026. The vendor confirmed active exploitation with at least one reported victim. JPCERT/CC issued alert JPCERT-AT-2026-0004 on the same date, warning that vulnerable instances remain accessible in Japan and that exploitation is expected to increase as vulnerability details become public.

CISA added CVE-2026-25108 to the Known Exploited Vulnerabilities (KEV) catalog on February 24, 2026, establishing an emergency remediation deadline of March 17, 2026 for all US federal civilian executive branch agencies. This CISA KEV addition signals confirmed exploitation and elevates the threat to critical priority.

FileZen has a history of being targeted by advanced threat actors. In 2021, Japanese government agencies including the Cabinet Office and multiple prefectural governments were compromised through FileZen vulnerabilities (CVE-2020-5639, CVE-2021-20655), with data exfiltration affecting hundreds of thousands of records. The product's concentration in sensitive Japanese government and enterprise environments makes it a high-value target for espionage-motivated threat actors.

The FileZen V4.x branch has reached end-of-support, meaning no dedicated patch is available — users must upgrade to V5.0.11. The vendor recommends that organizations that may have been compromised should change all user passwords, as successful exploitation implies the attacker had at least one valid account credential. FileZen provides a system directory file monitoring feature that may capture exploitation artifacts in logs, but there is no dedicated exploitation detection mechanism built into the product.

FileZen S (the newer cloud-based offering) is explicitly not affected by this vulnerability.

MITRE ATT&CK techniques used in TL-2026-0169

execution

T1059.004 Unix Shell; T1203 Exploitation for Client Execution

privilege-escalation

T1068 Exploitation for Privilege Escalation

defense-evasion

T1070.004 File Deletion; T1078 Valid Accounts

command-and-control

T1071.001 Web Protocols

collection

T1074.001 Local Data Staging; T1213 Data from Information Repositories

discovery

T1082 System Information Discovery; T1083 File and Directory Discovery

credential-access

T1110 Brute Force

initial-access

T1190 Exploit Public-Facing Application

impact

T1485 Data Destruction

exfiltration

T1567 Exfiltration Over Web Service

Affected products and versions in CVE-2026-25108 Soliton FileZen OS Command Injection

  • Soliton Systems — FileZen
    Vulnerable versions: V4.2.1 through V4.2.8; V5.0.0 through V5.0.10
    Fixed in: V5.0.11

Remediation for CVE-2026-25108 Soliton FileZen OS Command Injection

Patches

  • FileZen V5.0.11 — released January 13, 2026 by Soliton Systems
  • No patch for V4.x branch — end-of-support, must upgrade to V5.0.11

Immediate actions

  • Update FileZen to V5.0.11 or later immediately
  • If running V4.x, upgrade to V5.0.11 — no V4.x patch available (end-of-support)
  • Change all FileZen user passwords if compromise is suspected
  • Review FileZen system directory file monitoring logs for exploitation artifacts
  • Restrict network access to FileZen admin and user interfaces to trusted IP ranges
  • Disable the Antivirus Check Option temporarily if immediate patching is not possible

Workarounds

  • Disable BitDefender Antivirus Check Option to remove exploitation precondition
  • Restrict FileZen web interface access to trusted networks only
  • Enforce strong password policies and audit user accounts for unauthorized access

Longer-term hardening

  • Migrate from FileZen to FileZen S (cloud-based, not affected by this CVE)
  • Implement network segmentation for file transfer appliances
  • Deploy web application firewall rules to detect command injection patterns in HTTP requests
  • Implement MFA for all FileZen user accounts to raise exploitation barrier
  • Monitor for anomalous process execution from FileZen service context
  • Establish regular firmware update cadence for all file transfer appliances

CVEs associated with CVE-2026-25108 Soliton FileZen OS Command Injection

CVE-2026-25108

Weaknesses (CWE) in CVE-2026-25108 Soliton FileZen OS Command Injection

CWE-78

Timeline of CVE-2026-25108 Soliton FileZen OS Command Injection

  • Soliton Systems releases FileZen V5.0.11 firmware update fixing CVE-2026-25108. Distributed to maintenance contract customers.
  • JPCERT/CC publishes alert confirming active exploitation and warning that vulnerable FileZen instances remain accessible in Japan. Source: https://www.jpcert.or.jp/at/2026/at260004.html
  • Soliton Systems publicly discloses CVE-2026-25108 via vendor advisory. JVN publishes JVN#84622767. JPCERT/CC issues alert JPCERT-AT-2026-0004 confirming active exploitation.
  • Soliton Systems updates vendor advisory with additional exploitation details and guidance for compromise verification.
  • NVD publishes CVE-2026-25108 entry with CVSS 8.8 score and references to JVN, CISA, and Soliton advisories.
  • CISA adds CVE-2026-25108 to Known Exploited Vulnerabilities catalog. Emergency remediation deadline set for 2026-03-17 for US federal agencies. Source: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  • CISA emergency remediation deadline for CVE-2026-25108. All US federal civilian executive branch agencies must have patched or mitigated by this date.
  • As of 2026-05-29, CVE-2026-25108 (Soliton FileZen OS command injection) remains a patched flaw (V5.0.11, 2026-01-13) but is still actively exploited per CISA KEV and JPCERT/CC, with the 2026-03-17 federal deadline now past. Unpatched V4.x (EOL) and V5.0.0-V5.0.10 appliances stay at risk; no attribution or successor reported, so PATCHED holds.

Sources cited for CVE-2026-25108 Soliton FileZen OS Command Injection

Detection coverage for TL-2026-0169

As of 2026-03-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0169 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
16 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats