The Containment Era is here. →Explore

Executive Summary

In October 2025, Gladinet patched a critical zero-day vulnerability (CVE-2025-11371) in its CentreStack file-sharing software, which had been exploited by threat actors since late September. The attackers leveraged a local file inclusion flaw to access the application's Web.config file and extract the machine key, subsequently exploiting a chained deserialization vulnerability (CVE-2025-30406) to achieve unauthenticated remote code execution. The service's SYSTEM-level privileges enabled lateral movement and sensitive file access. Gladinet released mitigations and a full patch, urging immediate client upgrades to prevent further compromise of business environments.

This incident highlights a continuing trend in targeting widely used business collaboration platforms via sophisticated vulnerability chaining, often bypassing previous mitigations. The exploitation’s speed and public proof-of-concept release underscore the growing urgency for rapid patch management and proactive threat detection across enterprise SaaS deployments.

Why This Matters Now

Zero-day vulnerabilities in business-critical software are rapidly exploited in the wild, with attackers leveraging chained flaws and published proof-of-concepts to bypass established safeguards. Organizations relying on file-sharing platforms must prioritize prompt patching and apply Zero Trust strategies to limit lateral movement and protect sensitive data.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Attackers exploited a local file inclusion vulnerability (CVE-2025-11371) to access sensitive files and chained it with a deserialization flaw (CVE-2025-30406) to achieve remote code execution.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Proper application of Zero Trust and CNSF controls—such as segmentation, policy-driven access enforcement, inline intrusion prevention, and strong egress filtering—would have raised significant barriers at each kill chain step, reducing both attacker freedom and business risk. Granular visibility and threat detection would enable rapid response to anomalous behaviors like unauthorized file access or suspicious outbound activity.

Initial Compromise

Control: Cloud Firewall (ACF)

Mitigation: Blocked unauthorized inbound traffic and exploitation attempts.

Privilege Escalation

Control: Inline IPS (Suricata)

Mitigation: Detected and blocked signature-based exploit and privilege escalation payloads.

Lateral Movement

Control: Zero Trust Segmentation

Mitigation: Prevented unauthorized workload-to-workload communication and lateral movement.

Command & Control

Control: Threat Detection & Anomaly Response

Mitigation: Raised alerts on anomalous connections and unusual command sequences.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Blocked or alerted on unsanctioned data transfers and unauthorized egress.

Impact (Mitigations)

Enabled rapid identification and containment of affected assets and flows.

Impact at a Glance

Affected Business Functions

  • File Sharing Services
  • Data Storage Management
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: $50,000

Data Exposure

Potential exposure of sensitive configuration files, including cryptographic keys, leading to unauthorized access and data breaches.

Recommended Actions

  • Prioritize immediate patching of vulnerable applications (such as CentreStack) and routinely validate cloud app configurations.
  • Enforce granular Zero Trust segmentation with identity-based, least-privilege policies to restrict lateral movement within cloud and hybrid environments.
  • Deploy inline intrusion prevention and threat detection capabilities to detect and block deserialization and RCE exploit attempts in real time.
  • Strengthen outbound (egress) filtering and policy enforcement to prevent unauthorized data exfiltration and command & control communication.
  • Invest in unified, multi-cloud visibility and centralized policy management to accelerate detection, containment, and incident response across distributed architectures.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image