The Containment Era is here. →Explore

Executive Summary

In November 2025, the Cybersecurity and Infrastructure Security Agency (CISA) identified and announced active exploitation of two critical vulnerabilities: CVE-2025-11371 in Gladinet CentreStack and Triofox (files or directories exposed to external parties), and CVE-2025-48703 in CWP Control Web Panel (an OS command injection flaw). Threat actors are leveraging these weaknesses to gain unauthorized file access or execute malicious code within affected environments, targeting organizations across sectors. The vulnerabilities enable lateral movement, data exfiltration, and potentially full compromise, with significant risk to sensitive data, business operations, and regulatory posture for organizations running vulnerable systems.

This announcement underscores a broader trend of attackers exploiting unpatched software vulnerabilities in common enterprise tools. With automatic exploitation kits and a growing focus on file-sharing and web panel infrastructure, organizations face urgent pressure to accelerate vulnerability management and adopt Zero Trust practices to contain and monitor internal threats.

Why This Matters Now

The immediate, active exploitation of these vulnerabilities puts countless public and private sector organizations at risk of data breaches, business disruption, and compliance violations. With attackers rapidly automating campaigns against exposed systems, there is a critical need to identify, patch, and monitor vulnerable assets to prevent compromise.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Exploiting these vulnerabilities can lead to violations of HIPAA, PCI, and NIST standards due to unauthorized access, insufficient data encryption, and lack of segmentation, risking regulatory penalties and reputational damage.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Zero Trust segmentation, east-west traffic security, egress filtering, and inline intrusion prevention would have provided early detection, reduced attack surface, and limited lateral movement and data exfiltration. CNSF-aligned controls enforce least privilege, inspect traffic, and rapidly alert on suspicious behaviors at each stage, minimizing overall attack impact.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Inline detection and policy enforcement would detect and block suspicious exploit traffic.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Microsegmentation and least privilege boundaries prevent cross-access to privileged services.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Internal traffic inspection detects and blocks unauthorized workload-to-workload movement.

Command & Control

Control: Egress Security & Policy Enforcement

Mitigation: Outbound C2 activity is detected and blocked based on policy and threat intelligence.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Data loss is prevented by restricting and monitoring outbound connectivity.

Impact (Mitigations)

Rapid detection and response limits operational impact.

Impact at a Glance

Affected Business Functions

  • File Sharing Services
  • Web Hosting Services
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: $50,000

Data Exposure

Potential exposure of sensitive system files and unauthorized remote code execution leading to data breaches.

Recommended Actions

  • Prioritize patching of all systems affected by KEV-listed vulnerabilities such as those in CentreStack and CWP Control Web Panel.
  • Implement Zero Trust segmentation and least privilege access to isolate workloads and reduce lateral movement opportunities.
  • Enforce egress filtering and outbound policy controls to block unauthorized C2 and data exfiltration.
  • Deploy threat detection and anomaly response tooling to monitor for exploit patterns and abnormal behaviors across cloud environments.
  • Leverage inline cloud-native enforcement, east-west inspection, and centralized visibility for rapid detection, investigation, and mitigation of emerging threats.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image