Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Gladinet CentreStack And Triofox 0-Day RCE Vulnerability Actively Exploited In Attacks

A zero-day vulnerability, identified as CVE-2025-11371 , affecting Gladinet CentreStack and Triofox products, is being actively exploited. The vulnerability is an unauthenticated Local File Inclusion (LFI) flaw that allows remote code execution (RCE) on…

A zero-day vulnerability, identified as CVE-2025-11371 , affecting Gladinet CentreStack and Triofox products, is being actively exploited. The vulnerability is an unauthenticated Local File Inclusion (LFI) flaw that allows remote code execution (RCE) on affected systems.

Currently, there is no official patch available. However, a mitigation has been provided, and organizations using the affected software are advised to implement the workaround immediately to prevent potential exploitation, as confirmed attacks have been reported by Huntress.

New Attack Bypasses Previous Security Patch

The zero-day exploitation was discovered by Huntress analysts following an alert on September 27, 2025. The alert indicated suspicious activity on a server running Gladinet CentreStack, initially thought to be related to a previously disclosed vulnerability, CVE-2025-30406. This earlier flaw involved a hardcoded machine key exploited through a ViewState deserialization attack.

Despite the system being patched against CVE-2025-30406, further analysis revealed a new attack chain. Threat actors were exploiting the LFI vulnerability, CVE-2025-11371, to access the machine key, enabling them to perform the same ViewState deserialization method and execute arbitrary code.

A zero-day vulnerability, identified as CVE-2025-11371 , affecting Gladinet CentreStack and Triofox products, is being actively exploited.
Jonathan Pierce · Thehackingpost

Huntress reported observing this exploit used against three of its customers. Initial signs of an attack were detected on September 26, 2025, when an anomalous base64 payload was executed as a child process of a web server.

Huntress confirmed that Gladinet was aware of the issue and was working with customers to apply a workaround. Huntress has also informed its affected partners directly.

In the absence of an official patch and with confirmed active exploitation, it is critical for organizations using CentreStack and Triofox to apply the recommended mitigation. Administrators are advised to disable the temp handler within the file for the UploadDownloadProxy .

Advertisement

This configuration change will disrupt some platform functionality but will effectively close the attack vector until a permanent patch is released by Gladinet. Due to the severity of the RCE vulnerability, system administrators should prioritize implementing this mitigation to protect their environments from potential exploitation.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories