FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user may send a specially crafted HTTP request to execute an arbitrary OS command.
Is CVE-2026-25108 exploited?
Listed in the CISA KEV catalog on 2026-02-24.
Federal remediation due 2026-03-17.
Past that date by 151 days.
EPSS puts exploitation in the next 30 days at 5%.
Public exploit code: none found in monitored sources.
Which products and versions are affected?
No affected package list recorded here yet.
Is there a patch?
No patch identifier recorded here yet.
What PlainSec published about CVE-2026-25108
PlainSec has not published a story about this CVE.