Reference page — cumulative record through Wednesday, October 7, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-25108
Soliton Systems K.K FileZen
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N H H H 8.7 .0518 92.2 YES
AFFECTED
Product Versions Fixed
FileZen V5.0.0 to V5.0.10 – —
FileZen V4.2.1 to V4.2.8 – —
TIMELINE
Jan 30 Reserved by jpcert
Feb 13 Published (CNA: jpcert)
Feb 24 Added to CISA KEV, remediation due 2026-03-17
Description
FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user may send a specially crafted HTTP request to execute an arbitrary OS command.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| January 30, 2026 | Reserved | Reserved by jpcert |
| February 13, 2026 | Published | Published (CNA: jpcert) |
| February 24, 2026 | KEV ADDED | Added to CISA KEV, remediation due 2026-03-17 |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-25108 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, October 7, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.