logo

Gladinet fixes actively exploited zero-day in file-sharing software

ID: 72333e26-165d-51dd-a7c6-8c7c7c3c6e13

STIX ID: report--72333e26-165d-51dd-a7c6-8c7c7c3c6e13

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2025-10-16

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

Gladinet CentreStack was actively targeted via a local file inclusion zero-day (CVE-2025-11371) that lets attackers read Web.config to obtain the ASP.NET machine key and then chain to a deserialization RCE (CVE-2025-30406). Huntress observed live exploitation, released technical details and a minimal PoC for the LFI, and Gladinet published a security update (CentreStack version 16.10.10408.56683) and recommended mitigations (disable the temp handler) for unpatched systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.