How we count
Every figure on this page is a direct count of entries in CISA’s Known Exploited Vulnerabilities catalog attributed by CISA to Gladinet (KEV field vendorProject), refreshed daily. “Ransomware-linked” counts entries CISA marks as known to be used in ransomware campaigns; the remainder are “unknown” to CISA, not confirmed ransomware-free. A KEV listing means the vulnerability has been observed exploited in the wild. Snapshot as of 2026-09-02.
Exploited Gladinet vulnerabilities (CISA KEV)
| CVE | Product | Vulnerability | Added | |
|---|---|---|---|---|
| CVE-2025-14611 | CentreStack and Triofox | Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability | 2025-12-15 | |
| CVE-2025-12480 | Triofox | Gladinet Triofox Improper Access Control Vulnerability | 2025-11-12 | |
| CVE-2025-11371 | CentreStack and Triofox | Gladinet CentreStack and Triofox Files or Directories Accessible to External Parties Vulnerability | 2025-11-04 | |
| CVE-2025-30406 | CentreStack | Gladinet CentreStack and Triofox Use of Hard-coded Cryptographic Key Vulnerability | 2025-04-08 |
← All vendors by exploited-vulnerability count
🤖 Generated by defend.network from the CISA KEV catalog. Counts are deterministic aggregates of official CISA data; verify individual advisories at the linked sources.