Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

CISA Warns of Gladinet CentreStack and Triofox Files Vulnerability Exploited in Attacks

The Cybersecurity and Infrastructure Security Agency has issued a critical warning regarding a newly identified vulnerability affecting Gladinet CentreStack and Triofox platforms.

The Cybersecurity and Infrastructure Security Agency has issued a critical warning regarding a newly identified vulnerability affecting Gladinet CentreStack and Triofox platforms.

The flaw, tracked as CVE-2025-11371 , exposes sensitive system files and directories to unauthorized external access, potentially compromising organizations relying on these file-sharing solutions for business operations.

These files or directories accessible to external parties allow attackers to discover and retrieve confidential system information without proper authentication.

The vulnerability stems from improper access controls within the affected applications, classified under CWE-552, which specifically addresses issues where sensitive resources remain accessible to unintended actors.

Security researchers have confirmed active exploitation attempts targeting vulnerable deployments, prompting immediate federal agency intervention.

The vulnerability 11371 creates a significant exposure window for attackers attempting to gather reconnaissance data or launch follow-up attacks.

By accessing exposed directories, threat actors can identify system configurations, user information, and potentially hardcoded credentials information commonly leveraged in multi-stage attack chains.

Security researchers have confirmed active exploitation attempts targeting vulnerable deployments, prompting immediate federal agency intervention.
Jason Ford · Thehackingpost

While the vulnerability has not yet been publicly linked to ransomware campaigns, cybersecurity experts warn that the accessible information could enable devastating ransomware deployments.

CVE IDVulnerability TypeAffected ProductsCVE-2025-11371Files or Directories Accessible to External PartiesGladinet CentreStack, Triofox CISA has assigned this vulnerability a remediation deadline of November 25, 2025, providing organizations approximately three weeks to implement protective measures.

The agency recommends three primary mitigation strategies depending on organizational capability and risk tolerance. First, organizations should immediately apply all vendor-supplied patches and security updates.

Second, federal agencies managing cloud services should implement controls aligned with Binding Operational Directive 22-01, which mandates specific security baselines for government cloud infrastructure .

Third, organizations unable to patch or implement equivalent protections are advised to discontinue using the product entirely.

Advertisement

Organizations currently deploying Gladinet CentreStack or Triofox should prioritize verification of their current software versions and check e Network administrators should review access logs to identify any suspicious file access attempts or unusual data queries.

Implementing network segmentation, restricting external access to administrative interfaces, and deploying enhanced monitoring solutions can provide interim protection while patches are applied.

The vulnerability underscores ongoing challenges with cloud-based file-sharing platforms and the critical importance of maintaining updated security postures.

Follow us on Google News , LinkedIn , and X for daily cybersecurity updates. Contact us to feature your stories.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories