CVE-2026-25108
CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th
FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user may send a specially crafted HTTP request to execute an arbitrary OS command.
| Vendor | soliton systems k.k. |
| Product | filezen |
| Published | Feb 13, 2026 |
| Last Updated | Feb 26, 2026 |
โ ๏ธ Actively Exploited โ Act Now
Get instant alerts for soliton systems k.k. filezen
This vulnerability is actively exploited in the wild. Set up free real-time alerts so you're first to know about threats like CVE-2026-25108.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Versions
Soliton Systems K.K. / FileZen
V5.0.0 to V5.0.10
Soliton Systems K.K. / FileZen
V4.2.1 to V4.2.8