Federal News
CISA Urges Federal Agencies to Patch Wing FTP Server
March 18, 2026
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a directive for all U.S. federal agencies to patch a medium-severity vulnerability (CVE-2025-47813) in Wing FTP Server software by March 30, 2026, or discontinue its use. This vulnerability, which leaks server paths, is actively exploited in chained cyberattacks and poses significant risks to federal IT systems. Under Binding Operational Directive (BOD) 22-01, federal civilian agencies are mandated to remediate this flaw within two weeks of notification to prevent exploitation. This action underscores the critical need for timely vulnerability management and patching in federal procurement and IT operations.
- Why this matters: Federal agencies must prioritize patching or replacing affected Wing FTP Server instances to comply with CISA mandates and mitigate cybersecurity risks.
- Procurement professionals should evaluate current contracts and vendor software for exposure to this vulnerability and plan for potential updates or replacements.
- Cybersecurity vendors and contractors can anticipate increased demand for vulnerability assessment, patch management services, and secure file transfer solutions.
- Organizations supporting federal IT should align their security compliance efforts with BOD 22-01 deadlines to avoid operational disruptions and maintain federal cybersecurity standards.
Agencies
Cybersecurity and Infrastructure Security Agency, Federal Civilian Executive Branch, US Air Force
Vendors
Wing FTP Server
Locations
Sources
- Federal agencies urged to patch Wing FTP Server flaw following CISA warning · MSN · Mar 18
- CISA flags Wing FTP Server flaw as actively exploited in attacks · BleepingComputer · Mar 16
- Federal agencies urged to patch Wing FTP Server flaw following CISA warning · MSN · Mar 18