Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
CISA Identifies Exploited Wing FTP Vulnerability

CISA Identifies Exploited Wing FTP Vulnerability

Posted on March 17, 2026 By CWS

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently added a medium-severity flaw in Wing FTP to its catalog of Known Exploited Vulnerabilities (KEV). This decision comes in response to evidence of ongoing exploitation of the vulnerability. Identified as CVE-2025-47813 and carrying a CVSS score of 4.3, this flaw involves the unintended exposure of installation paths under specific conditions.

Details of the Wing FTP Vulnerability

The vulnerability, as outlined by CISA, is triggered when a long value is input in the UID cookie, causing error messages that reveal sensitive information. This issue affects all software versions up to and including 7.4.3. The security loophole has been rectified in version 7.4.4, released in May, thanks to responsible disclosure by RCE Security researcher Julien Ahrens.

Additionally, version 7.4.4 addresses another critical vulnerability, CVE-2025-47812, which has a CVSS score of 10.0. This separate flaw allows for remote code execution and has been actively exploited since July 2025.

Exploitation and Patches

According to Huntress, attackers have utilized CVE-2025-47812 to execute malicious Lua files, perform reconnaissance, and install remote monitoring software. A proof-of-concept exploit, shared by Ahrens on GitHub, demonstrates that the endpoint at “/loginok.html” fails to properly validate the UID session cookie. If the provided value exceeds the operating system’s maximum path length, it results in an error message that discloses the local server path.

Such successful exploits can enable authenticated attackers to ascertain the local server path, potentially aiding in further exploitation of vulnerabilities like CVE-2025-47812.

Recommendations for Agencies

As of now, there is no detailed information on the exploitation methods being used in the wild, nor is it clear if this vulnerability is being exploited alongside CVE-2025-47812. In response to these developments, Federal Civilian Executive Branch (FCEB) agencies are advised to implement the necessary updates by March 30, 2026.

This proactive measure is crucial in mitigating potential risks associated with these vulnerabilities, underscoring the importance of timely software updates to safeguard network infrastructures.

The Hacker News Tags:CISA, CVE-2025-47813, Cybersecurity, FCEB agencies, information disclosure, network security, remote code execution, software patch, Vulnerability, Wing FTP

Post navigation

Previous Post: RondoDox Botnet’s Expansive Exploit Arsenal and IP Tactics
Next Post: Researchers Unveil Vulnerability in Palo Alto’s Cortex XDR

Related Posts

Nation-State Hacks, Spyware Alerts, Deepfake Malware, Supply Chain Backdoors Nation-State Hacks, Spyware Alerts, Deepfake Malware, Supply Chain Backdoors The Hacker News
Cloud Password Managers Face Security Challenges Cloud Password Managers Face Security Challenges The Hacker News
Zoom and Xerox Release Critical Security Updates Fixing Privilege Escalation and RCE Flaws Zoom and Xerox Release Critical Security Updates Fixing Privilege Escalation and RCE Flaws The Hacker News
Microsoft Addresses High-Severity Windows Admin Center Flaw Microsoft Addresses High-Severity Windows Admin Center Flaw The Hacker News
Behavioral Analytics Crucial in AI Cybersecurity Threats Behavioral Analytics Crucial in AI Cybersecurity Threats The Hacker News
Iran Slows Internet to Prevent Cyber Attacks Amid Escalating Regional Conflict Iran Slows Internet to Prevent Cyber Attacks Amid Escalating Regional Conflict The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Government Servers Compromised Through cPanel Vulnerability
  • Trellix Faces Security Breach in Source Code Repository
  • New Security Flaws in Exim Mail Server Demand Immediate Patch
  • Bluekit Phishing Kit Leverages AI for Advanced Features
  • Cybercriminals Exploit Google Services in Facebook Phishing

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Government Servers Compromised Through cPanel Vulnerability
  • Trellix Faces Security Breach in Source Code Repository
  • New Security Flaws in Exim Mail Server Demand Immediate Patch
  • Bluekit Phishing Kit Leverages AI for Advanced Features
  • Cybercriminals Exploit Google Services in Facebook Phishing

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark