CISA Sounds the Alarm: New Vulnerabilities Added to Exploited Catalog – Patch Now or Pay Later!

CISA has added Gladinet CentreStack and CWP Control Web Panel flaws to its Known Exploited Vulnerabilities catalog. These flaws, including a spicy OS command injection vulnerability, could make your IT department’s hair stand on end. Federal agencies have until November 25 to patch these vulnerabilities—or face wrath akin to forgetting your anniversary.

Pro Dashboard

Hot Take:

Looks like CISA is updating its digital shopping list of vulnerabilities. This time, they’ve added a couple of new ‘must-fix’ items that are hotter than a jalapeño on a summer day. Think of it as Black Friday for cybercriminals, but with no discounts and a lot more paperwork for IT departments. Stay safe out there, folks — and remember, patching is the new black!

Key Points:

  • CISA adds two new vulnerabilities to its Known Exploited Vulnerabilities Catalog.
  • CentreStack and Triofox’s Local File Inclusion flaw (CVE-2025-11371) can be exploited to access system files without authentication.
  • CWP Control Web Panel’s OS Command Injection flaw (CVE-2025-48703) allows remote command execution.
  • Federal agencies are required to patch these vulnerabilities by November 25, 2025.
  • Private organizations are also advised to address these vulnerabilities.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?