HomeIntelligenceBrief
🛡️ VULNERABILITY BRIEF🟡 Medium🛡️ Vulnerability

Active Exploitation of Wing FTP Information Disclosure (CVE‑2025‑47813) Leaks Server Paths

CISA has flagged an actively exploited information‑disclosure flaw in Wing FTP Server (CVE‑2025‑47813) that reveals installation paths. The vulnerability, rated CVSS 4.3, poses a supply‑chain risk for organizations that rely on third‑party FTP services to move sensitive data.

🛡️ LiveThreat™ Intelligence · 📅 March 17, 2026· 📰 thehackernews.com
🟡
Severity
Medium
🛡️
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
5 recommended
📰
Source
thehackernews.com

Active Exploitation of Wing FTP Information Disclosure (CVE‑2025‑47813) Leaks Server Paths

What It Is — A medium‑severity information‑disclosure flaw in Wing FTP Server (CVE‑2025‑47813) reveals the installation directory of the application when certain error conditions are triggered. The vulnerability scores CVSS 4.3.

Exploitability — CISA has placed the flaw in its Known Exploited Vulnerabilities (KEV) catalog, confirming that threat actors are actively leveraging the bug in the wild. Public PoCs have been observed in underground forums.

Affected Products — Wing FTP Server 7.x‑8.x (Windows and Linux deployments).

TPRM Impact

  • Third‑party file‑transfer services that host sensitive data may expose internal path structures, facilitating subsequent privilege‑escalation or ransomware attacks.
  • Organizations that rely on Wing FTP as a supply‑chain component could inherit the risk without direct control over patching schedules.

Recommended Actions

  • Verify whether Wing FTP Server is used by any critical vendors or internal teams.
  • Apply the vendor‑released patch (or upgrade to the latest major version) immediately.
  • Conduct a configuration review to ensure error messages do not disclose file system details.
  • Update incident‑response playbooks to include detection of anomalous FTP requests that enumerate paths.
  • Monitor CISA KEV feeds for any new exploitation indicators.

Source: The Hacker News

📰 Original Source
https://thehackernews.com/2026/03/cisa-flags-actively-exploited-wing-ftp.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

🛡️

Monitor Your Vendor Risk with LiveThreat™

Get automated breach alerts, security scorecards, and intelligence briefs when your vendors are compromised.