CISA added CVE-2025-47813, a Wing FTP Server information-disclosure flaw, to its Known Exploited Vulnerabilities list after evidence of active exploitation. The medium-severity bug discloses the server's full local installation path via an overlong UID cookie; it was fixed in Wing FTP Server 7.4.4 but can aid attackers in chaining to other flaws.
Part of the PlainSec briefing for 2026-03-25