CISA's list that day

4 November 2025

On CISA added 2 vulnerabilities to its list of exploited vulnerabilities, in Gladinet CentreStack and Triofox and CWP Control Web Panel. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2025-11371Files or Directories Accessible to External PartiesGladinet CentreStack and TriofoxPatch this weekMetasploit module; EPSS 0.920.92
CVE-2025-48703OS Command InjectionCWP Control Web PanelPatch this weekEPSS 0.990.99