The Containment Era is here. →Explore

Executive Summary

In November 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added critical vulnerabilities impacting Gladinet and Control Web Panel (CWP) to its Known Exploited Vulnerabilities (KEV) catalog after confirming active exploitation in the wild. Attackers have leveraged CVE-2025-11371 and similar flaws, which expose sensitive files or directories, enabling unauthorized code execution and unauthorized access to critical business data. Exploitation techniques include remote access and privilege escalation, with incidents observed in both enterprise and cloud environments. The exploited weaknesses have led to compromised systems and elevated business risk for affected organizations.

This incident highlights an escalating trend in the exploitation of web-facing management panels and software supply chain components, making east-west traffic security and timely vulnerability management crucial for defenders. Regulatory and industry pressure is mounting as the pace and sophistication of attacks accelerate.

Why This Matters Now

Rapid weaponization of new vulnerabilities means organizations cannot afford delays in patching or in deploying robust segmentation, detection, and cloud controls. The ongoing exploitation of Gladinet and CWP flaws underscores the urgency for real-time visibility and automated policy enforcement to mitigate modern attack surface risks.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Gaps in patch management, vulnerability response, and internal segmentation were exposed, highlighting the need for mapped controls under NIST, PCI, and HIPAA.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Applying Zero Trust segmentation, advanced east-west controls, egress policy enforcement, and inline threat detection would have limited the adversary's ability to exploit vulnerabilities, move laterally, establish C2, and exfiltrate data, greatly reducing impact at each kill chain stage.

Initial Compromise

Control: Cloud Firewall (ACF)

Mitigation: Prevents unauthorized exposure and exploitation of vulnerable services.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Limits unauthorized privilege escalation by restricting access between workloads and management surfaces.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Detects and blocks unauthorized internal movement between cloud workloads.

Command & Control

Control: Inline IPS (Suricata)

Mitigation: Blocks known malicious C2 patterns and signatures.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Prevents unauthorized data transfer outside the organization.

Impact (Mitigations)

Detects destructive or anomalous actions in real time.

Impact at a Glance

Affected Business Functions

  • File Sharing
  • Remote Access
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: $50,000

Data Exposure

Potential exposure of sensitive system files, including configuration files and credentials, leading to unauthorized access and data breaches.

Recommended Actions

  • Enforce strict firewalling and cloud-native segmentation to eliminate exposed attack surfaces.
  • Implement real-time east-west inspection to block lateral movement and internal pivoting.
  • Apply granular egress controls to restrict and monitor all outbound data flows.
  • Deploy inline threat detection and anomaly response for rapid containment of emerging threats.
  • Continuously review and remediate vulnerable services with automated visibility across multi-cloud and hybrid environments.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image