TL;DR

['CISA has added CVE-2025-47813 to the Known Exploited Vulnerabilities Catalog due to active exploitation. Operators should prioritize remediating this vulnerability as part of their security practices.']

What happened

['CISA has identified CVE-2025-47813, a Wing FTP Server Information Disclosure Vulnerability, and added it to the Known Exploited Vulnerabilities Catalog based on evidence of exploitation.']

Why it matters for ops

['The vulnerability poses significant risks to federal enterprise networks. Timely remediation is critical for mitigating potential cyber threats.']

Mitigation

  • Apply available patches and updates to remediate CVE-2025-47813.
  • Conduct a thorough security assessment of systems running Wing FTP Server to identify any further vulnerabilities.

Action items

  • Remediate the vulnerability within the deadline specified by BOD 22-01 for FCEB agencies.
  • Prioritize remediation based on risk and impact assessments for all organizations.

Detection IOCs

  • Monitoring for unauthorized access or data exfiltration attempts from Wing FTP Server installations.
  • Review of system logs for anomalous activities related to the affected software version.

Source link

https://www.cisa.gov/news-events/alerts/2026/03/16/cisa-adds-one-known-exploited-vulnerability-catalog