Vulnerabilities · 182 days ago

CISA Adds Exploited Wing FTP Path Disclosure to KEV

CISA added CVE-2025-47813, a Wing FTP Server information-disclosure flaw, to its Known Exploited Vulnerabilities list after evidence of active exploitation. The medium-severity bug discloses the server's full local installation path via an overlong UID cookie; it was fixed in Wing FTP Server 7.4.4 but can aid attackers in chaining to other flaws.

CVE-2025-47813

NVD KEV

Known exploited · CISA KEV

CVSS 4.3 MEDIUM: loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using… EPSS 63% (99th percentile).

CISA federal remediation date Mar 30

Timeline

Sources

3 sources covering this story

Entities

Part of the PlainSec briefing for 2026-03-25

Editions

Related stories