CVE-2025-47813
Known exploited · CISA KEV
CVSS 4.3 MEDIUM: loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using… EPSS 63% (99th percentile).
CISA federal remediation date Mar 30
Vulnerabilities & Exploits · Web App Attack
The bug reveals the server's full local installation path via an overlong UID cookie and can be chained with other Wing FTP flaws. The vendor fixed it in Wing FTP Server 7.4.4; evidence shows active exploitation.
3 sources · Mar 17
Known exploited · CISA KEV
CVSS 4.3 MEDIUM: loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using… EPSS 63% (99th percentile).
CISA federal remediation date Mar 30
SecurityWeek
CISA Flags Year-Old Wing FTP Vulnerability as Exploited
Tracked as CVE-2025-47813, the flaw leads to the disclosure of the full local installation path of the application.
originalThe Hacker News
CISA Flags Actively Exploited Wing FTP Vulnerability Leaking Server Paths
CISA adds Wing FTP CVE-2025-47813 to KEV after active exploitation, exposing server paths and aiding attacks; patch by March 30, 2026.
originalBleepingComputer
CISA flags Wing FTP Server flaw as actively exploited in attacks
government agencies to secure their Wing FTP Server instances against an actively exploited vulnerability that may be chained in remote code execution attacks.
originalPart of the PlainSec briefing for 2026-03-18
Every edition of this story: Wing FTP Server Flaw Added to Federal KEV List