LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-25108

CVE-2026-25108 - Vulnerability Analysis

HighCVSS: 8.8

Last Updated: February 13, 2026

FileZen - Command Injection

Published: February 13, 2026Updated: February 13, 2026Remote Exploitable

Overview

FileZen contains a command injection caused by improper input handling in the virus check option, letting logged-in users execute arbitrary OS commands remotely, exploit requires user to be logged in.

Severity & Score

Severity: High
CVSS Score: 8.8
EPSS Score: 1858.7%(Probability of exploitation in next 30 days)

Impact

Logged-in users can execute arbitrary OS commands, potentially leading to full system compromise.

Mitigation

Update to the latest version with the vulnerability fixed.

Social Media Activity(1 post)

ZEN SecDB
ZEN SecDB
@secdb
Mar 1, 2026

📈 CVE Published in last 30 days (2026-01-30 - 2026-03-01) See more at https://secdb.nttzen.cloud/dashboard Total CVEs: 5003 Severity: - Critical: 448 - High: 1563 - Medium: 2229 - Low: 226 - None: 537 Status: - : 33 - Analyzed: 2258 - Awaiting Analysis: 2188 - Modified: 155 - Received: 89 - Rejected: 197 - Undergoing Analysis: 83 Top CNAs: - GitHub, Inc.: 907 - VulnCheck: 572 - VulDB: 519 - Patchstack: 385 - Wordfence: 361 - kernel.org: 259 - MITRE: 217 - Fortinet, Inc.: 102 - Intel Corporation: 84 - Apple Inc.: 76 Top Affected Products: - UNKNOWN: 2529 - Apple Macos: 64 - Mozilla Firefox: 54 - Mozilla Thunderbird: 51 - Apple Iphone Os: 49 - Apple Ipados: 49 - Openclaw: 35 - Imagemagick: 34 - Microsoft Windows Server 2025: 29 - Comodo Dome Firewall: 29 Top EPSS Score: - CVE-2026-1731 - 61.83 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-1731) - CVE-2026-2329 - 41.14 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-2329) - CVE-2026-22769 - 34.16 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-22769) - CVE-2026-25108 - 18.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-25108) - CVE-2026-2033 - 15.58 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-2033) - CVE-2020-37123 - 12.89 % (https://secdb.nttzen.cloud/cve/detail/CVE-2020-37123) - CVE-2026-1603 - 11.74 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-1603) - CVE-2026-1687 - 5.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-1687) - CVE-2020-37088 - 4.95 % (https://secdb.nttzen.cloud/cve/detail/CVE-2020-37088) - CVE-2026-1207 - 4.78 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-1207)

View original post

Details

CVE ID
CVE-2026-25108
Severity
High
CVSS Score
8.8
Type
command_injection
Status
unconfirmed
EPSS
1858.7%
Social Posts
1

CWE

  • CWE-78

CVSS Metrics

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Score

1858.7%Probability of exploitation in the next 30 days