Hackers on the Loose: New Security Vulnerabilities in Gladinet and Control Web Panel Exposed!
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two security vulnerabilities impacting Gladinet and Control Web Panel (CWP) to its Known Exploited Vulnerabilities catalog. These flaws could lead to unintended disclosure of system files and unauthenticated remote code execution, which is as bad as it sounds. Stay patched, folks.

Hot Take:
Ah, vulnerabilities, the gift that keeps on giving! As if hackers needed more reasons to celebrate, CISA just added two new party starters to their KEV catalog. Get ready for a bash with Gladinet and Control Web Panel flaws! These vulnerabilities are like piñatas filled with system files and unauthorized access—who wouldn’t want to take a swing?
Key Points:
- CISA adds two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2025-11371 and CVE-2025-48703.
- CVE-2025-11371 affects Gladinet CentreStack and Triofox, risking unintended disclosure of system files.
- CVE-2025-48703 affects Control Web Panel, allowing unauthenticated remote code execution via command injection.
- Federal agencies are rushing to patch these vulnerabilities by November 25, 2025.
- WordPress sites are also under threat, with three critical vulnerabilities in popular plugins and themes discovered.
Already a member? Log in here
