CISA's list that day
4 November 2025
On CISA added 2 vulnerabilities to its list of exploited vulnerabilities, in Gladinet CentreStack and Triofox and CWP Control Web Panel. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2025-11371Files or Directories Accessible to External Parties | Gladinet CentreStack and Triofox | Patch this weekMetasploit module; EPSS 0.92 | 0.92 | ||
| CVE-2025-48703OS Command Injection | CWP Control Web Panel | Patch this weekEPSS 0.99 | 0.99 |