logo

Hackers exploiting zero-day in Gladinet file sharing software

ID: f7367553-2c22-508c-8ce4-0d9b2f52e651

STIX ID: report--f7367553-2c22-508c-8ce4-0d9b2f52e651

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2025-10-10

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Threat actors are exploiting a zero-day Local File Inclusion (CVE-2025-11371) in Gladinet CentreStack and Triofox to retrieve the Web.config machine key and achieve remote code execution by chaining to a ViewState deserialization vulnerability (CVE-2025-30406). At least three companies were targeted; no patch is available yet and Huntress published mitigations (remove the temp handler in UploadDownloadProxy Web.config) while the vendor notifies customers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.