
CISA advised U.S. government organizations to protect their Wing FTP Server installations from a vulnerability being actively exploited, which could lead to remote code execution.
Wing FTP Server is a versatile FTP server application offering secure file transfers through SFTP and web servers. Its developers boast over 10,000 global users, including prominent entities like the U.S. Air Force, Sony, Airbus, Reuters, and Sephora.
Identified as CVE-2025-47813, this weakness lets attackers with limited access uncover the application’s complete local installation path on vulnerable servers.
“Wing FTP Server exhibits a vulnerability where sensitive information is exposed within error messages when a lengthy value is used in the UID cookie,” CISA stated.
The developers addressed it in May 2025 with Wing FTP Server v7.4.4, alongside a critical remote code execution (RCE) issue (CVE-2025-47812) and an information disclosure problem (CVE-2025-27889) that could be used to steal user passwords.
The RCE flaw had previously been identified as actively exploited after threat actors started exploiting it shortly after its details became public.
Security expert Julien Ahrens, who found and reported the vulnerabilities, also shared exploit code for CVE-2025-47813 in June, suggesting attackers might use it with CVE-2025-47812.
On Tuesday, CISA included CVE-2025-47813 in its list of actively exploited vulnerabilities, giving Federal Civilian Executive Branch (FCEB) agencies two weeks to secure their systems, as instructed by Binding Operational Directive (BOD) 22-01 from November 2021.
Although BOD 22-01 focuses on federal agencies, CISA encourages all users, particularly those in the private sector, to patch their servers to prevent potential attacks.
“This kind of vulnerability is often used by malicious actors and poses serious threats to the federal government,” CISA cautioned on Monday.
“Implement vendor mitigations, adhere to BOD 22-01 guidelines for cloud services, or stop using the product if fixes are not available.”
#agency #attackers. #being #cisa #currently #cybersecurity #ftp #news #security #server #that #used #vulnerability #warns #wing — News
© Bulletproof Servers. All rights reserved.