The Containment Era is here. →Explore

Executive Summary

In October 2025, threat actors exploited a zero-day vulnerability (CVE-2025-11371) in Gladinet’s CentreStack and Triofox file sharing solutions, used by thousands of businesses worldwide. The flaw, a local file inclusion (LFI) bug present in all current product versions, was leveraged to extract sensitive configuration data and trigger a previously known deserialization vulnerability (CVE-2025-30406), resulting in remote code execution (RCE). At least three organizations have confirmed exploitation as attackers gained unauthorized access before Gladinet issued a patch, forcing emergency mitigations that affected platform functionality.

This incident highlights how chained vulnerabilities and rapid exploitation of zero-days continue to threaten cloud-based file sharing services. With attackers escalating LFI into full RCE, organizations face heightened pressure to improve visibility, patch agility, and enforce Zero Trust controls, especially amid growing regulatory scrutiny.

Why This Matters Now

The rapid weaponization of chained zero-day vulnerabilities in critical business applications spotlights urgent gaps in segmentation, east-west traffic security, and proactive threat detection. Organizations relying on third-party cloud file sharing platforms must urgently review controls, as unpatched LFI and deserialization flaws can enable full system compromise before defenses or patches are deployed.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Attackers chained a local file inclusion (CVE-2025-11371) and a deserialization bug (CVE-2025-30406) to gain unauthorized access and execute remote code on all product versions.

Cloud Native Security Fabric Mitigations and ControlsCNSF

CNSF controls such as zero trust segmentation, inline visibility, east-west security, egress policy enforcement, and anomaly detection would have minimized attack progression. Segmenting workloads, monitoring unusual behaviors, and enforcing least-privilege network paths could have blocked or detected each kill chain stage.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Attack surface reduced and inline inspection at the perimeter to detect unauthorized access attempts.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Limits privilege escalation scope by restricting application-to-workload communication.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Lateral movement blocked via enforcement of workload-to-workload identity-based policies.

Command & Control

Control: Egress Security & Policy Enforcement

Mitigation: Detects and blocks suspicious or unauthorized outbound communication attempts.

Exfiltration

Control: Multicloud Visibility & Control

Mitigation: Exfiltration attempts detected and halted via centralized monitoring and policy.

Impact (Mitigations)

Early-stage threat activity is detected and automatic response is triggered.

Impact at a Glance

Affected Business Functions

  • File Sharing
  • Remote Access
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: $50,000

Data Exposure

Potential exposure of sensitive system files due to unauthenticated access.

Recommended Actions

  • Enforce zero trust segmentation and microsegmentation to limit exploit scope and block lateral movement.
  • Apply stringent east-west and egress traffic controls with continuous monitoring to flag anomalous behaviors and data exfiltration.
  • Rapidly deploy inline perimeter protections (CNSF) for vulnerability exploitation attempts with real-time alerting.
  • Leverage centralized multicloud visibility for early detection and broad policy enforcement to constrain attacker opportunities.
  • Integrate anomaly detection and automated response capabilities to minimize breach dwell time and reduce business impact.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image