# CVE-2026-25108 Soliton FileZen OS Command Injection — CISA KEV Active Exploitation of Japan-Market File Transfer Appliance

> Soliton Systems FileZen, a file sharing and transfer appliance widely deployed in Japanese government and enterprise environments, contains an OS command injection vulnerability (CVE-2026-25108, CVSS 8.8) that is being actively exploited in the wild. CISA added this to the KEV catalog on 2026-02-24 with an emergency remediation deadline of 2026-03-17.

- **Published:** 2026-03-02T15:47:00Z
- **Last reviewed:** 2026-03-02T15:47:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0169
- **ID:** TL-2026-0169
- **Severity:** CRITICAL (CVSS 8.8)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 16 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-25108

## Description

CVE-2026-25108 is an OS command injection vulnerability (CWE-78) in Soliton Systems FileZen, a file sharing and transfer appliance predominantly deployed across Japanese government agencies, financial institutions, and enterprise environments. The vulnerability affects FileZen versions V4.2.1 through V4.2.8 and V5.0.0 through V5.0.10, and was patched in V5.0.11 released on January 13, 2026.

The vulnerability exists in the post-authentication web interface and can be exploited when the FileZen Antivirus Check Option (powered by BitDefender) is enabled. An authenticated user can send specially crafted HTTP requests to inject arbitrary OS commands that execute on the underlying operating system with the privileges of the FileZen service. This means exploitation requires two preconditions: (1) the BitDefender antivirus check option must be active, and (2) the attacker must possess valid credentials for at least one user account.

Soliton Systems coordinated disclosure with JPCERT/CC, publishing JVN#84622767 on February 13, 2026. The vendor confirmed active exploitation with at least one reported victim. JPCERT/CC issued alert JPCERT-AT-2026-0004 on the same date, warning that vulnerable instances remain accessible in Japan and that exploitation is expected to increase as vulnerability details become public.

CISA added CVE-2026-25108 to the Known Exploited Vulnerabilities (KEV) catalog on February 24, 2026, establishing an emergency remediation deadline of March 17, 2026 for all US federal civilian executive branch agencies. This CISA KEV addition signals confirmed exploitation and elevates the threat to critical priority.

FileZen has a history of being targeted by advanced threat actors. In 2021, Japanese government agencies including the Cabinet Office and multiple prefectural governments were compromised through FileZen vulnerabilities (CVE-2020-5639, CVE-2021-20655), with data exfiltration affecting hundreds of thousands of records. The product's concentration in sensitive Japanese government and enterprise environments makes it a high-value target for espionage-motivated threat actors.

The FileZen V4.x branch has reached end-of-support, meaning no dedicated patch is available — users must upgrade to V5.0.11. The vendor recommends that organizations that may have been compromised should change all user passwords, as successful exploitation implies the attacker had at least one valid account credential. FileZen provides a system directory file monitoring feature that may capture exploitation artifacts in logs, but there is no dedicated exploitation detection mechanism built into the product.

FileZen S (the newer cloud-based offering) is explicitly not affected by this vulnerability.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1078 Valid Accounts
- T1059.004 Unix Shell
- T1203 Exploitation for Client Execution
- T1068 Exploitation for Privilege Escalation
- T1070.004 File Deletion
- T1110 Brute Force
- T1083 File and Directory Discovery
- T1082 System Information Discovery
- T1213 Data from Information Repositories
- T1074.001 Local Data Staging
- T1567 Exfiltration Over Web Service
- T1071.001 Web Protocols
- T1485 Data Destruction

## Sources

- [CISA KEV Entry — CVE-2026-25108](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-25108)
- [JVN Advisory JVN#84622767 — FileZen vulnerable to OS command injection](https://jvn.jp/en/jp/JVN84622767/)
- [Soliton Systems Vendor Advisory — FileZen Command Injection Vulnerability](https://www.soliton.co.jp/support/2026/006657.html)
- [JPCERT/CC Alert — JPCERT-AT-2026-0004 — FileZen OS Command Injection](https://www.jpcert.or.jp/at/2026/at260004.html)
- [NVD — CVE-2026-25108](https://nvd.nist.gov/vuln/detail/CVE-2026-25108)
- [JVNDB-2026-000023 — FileZen OS Command Injection](https://jvndb.jvn.jp/jvndb/JVNDB-2026-000023)
- [CVE Record — CVE-2026-25108](https://www.cve.org/CVERecord?id=CVE-2026-25108)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0169
