Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»CISA flags Wing FTP Server flaw as actively exploited in attacks
    Cybersecurity

    CISA flags Wing FTP Server flaw as actively exploited in attacks

    adminBy adminMarch 17, 2026No Comments2 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    CISA
    Share
    Facebook Twitter LinkedIn Pinterest Email

    CISA

    CISA warned U.S. government agencies to secure their Wing FTP Server instances against an actively exploited vulnerability that may be chained in remote code execution attacks.

    Wing FTP Server is a cross-platform FTP server software that also provides secure file transfer via its built-in SFTP and web servers. The developers claim that their file transfer software is used by more than 10,000 customers worldwide, including the U.S. Air Force, Sony, Airbus, Reuters, and Sephora.

    Tracked as CVE-2025-47813, the security flaw allows threat actors with low privileges to discover the full local installation path of the application on unpatched servers.

    “Wing FTP Server contains a generation of error message containing sensitive information vulnerability when using a long value in the UID cookie,” CISA explains.

    The developer patched it in May 2025 in Wing FTP Server v7.4.4, together with a critical remote code execution (RCE) bug (CVE-2025-47812) and an information disclosure flaw (CVE-2025-27889) that can be used to steal a user’s password.

    The RCE vulnerability was previously tagged as exploited in the wild after attackers began abusing it one day after technical details on the flaw became public.

    Security researcher Julien Ahrens, who discovered and reported the flaws, also shared proof-of-concept exploit code for CVE-2025-47813 in June and said attackers may exploit it as part of the same chain as CVE-2025-47812.

    On Tuesday, CISA added CVE-2025-47813 to its catalog of actively exploited vulnerabilities and gave Federal Civilian Executive Branch (FCEB) agencies two weeks to secure their systems, as mandated by the November 2021 Binding Operational Directive (BOD) 22-01.

    While BOD 22-01 targets only federal agencies, the U.S. cybersecurity agency encouraged all defenders, including those in the private sector, to patch their servers against ongoing attacks as soon as possible.

    “This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise,” CISA warned on Monday.

    “Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.”


    tines

    Malware is getting smarter. The Red Report 2026 reveals how new threats use math to detect sandboxes and hide in plain sight.

    Download our analysis of 1.1 million malicious samples to uncover the top 10 techniques and see if your security stack is blinded.

    Actively attacks CISA Exploited flags Flaw FTP Server Wing
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleSamsung Sound quality and effects 16.1.29 by Samsung Electronics Co., Ltd.
    Next Article Boox just fixed the one thing holding back my favorite Kindle replacement
    admin
    • Website

    Related Posts

    Stryker attack raises concerns about role of device management tool

    March 17, 2026

    Security Firm Executive Targeted in Sophisticated Phishing Attack

    March 17, 2026

    GlassWorm Attack Uses Stolen GitHub Tokens to Force-Push Malware Into Python Repos

    March 17, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    This Japanese SUV redefines affordable luxury

    March 17, 2026

    Stryker attack raises concerns about role of device management tool

    March 17, 2026

    What incrementality really means in affiliate marketing

    March 17, 2026

    Boox just fixed the one thing holding back my favorite Kindle replacement

    March 17, 2026
    Categories
    • Blogging (41)
    • Cybersecurity (811)
    • Privacy & Online Earning (123)
    • SEO & Digital Marketing (498)
    • Tech Tools & Mobile / Apps (995)
    • WiFi / Internet & Networking (132)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    This Japanese SUV redefines affordable luxury

    March 17, 2026

    Stryker attack raises concerns about role of device management tool

    March 17, 2026

    What incrementality really means in affiliate marketing

    March 17, 2026
    Most Popular
    • This Japanese SUV redefines affordable luxury
    • Stryker attack raises concerns about role of device management tool
    • What incrementality really means in affiliate marketing
    • Boox just fixed the one thing holding back my favorite Kindle replacement
    • CISA flags Wing FTP Server flaw as actively exploited in attacks
    • Samsung Sound quality and effects 16.1.29 by Samsung Electronics Co., Ltd.
    • Available’s $5B Project Qestrel aims to roll out 1,000 AI-ready edge data centers by year’s end
    • Security Firm Executive Targeted in Sophisticated Phishing Attack
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.