Vulnerabilities & Exploits · Web App Attack

Wing FTP Server Flaw Added to Federal KEV List

The bug reveals the server's full local installation path via an overlong UID cookie and can be chained with other Wing FTP flaws. The vendor fixed it in Wing FTP Server 7.4.4; evidence shows active exploitation.

3 sources · Mar 17

CVE-2025-47813

NVD KEV

Known exploited · CISA KEV

CVSS 4.3 MEDIUM: loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using… EPSS 63% (99th percentile).

CISA federal remediation date Mar 30

Timeline

Sources

Part of the PlainSec briefing for 2026-03-17

Every edition of this story: Wing FTP Server Flaw Added to Federal KEV List

More from today