CVE-2025-14611
Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
Yesterday's vulnerability disclosures included 1 critical CVE (CVSS 9.0+), a 67% decrease from the prior day's 3 critical issues. High-priority vulnerabilities totaled 30, representing a 33% reduction from 45. Five actively exploited vulnerabilities remain on the CISA KEV list, affecting Gladinet CentreStack/Triofox, Apple products, ASUS Live Update, Digiever DS-2105 Pro, and MongoDB Server. The single new critical vulnerability CVE-2025-14998 (CVSS 9.8) affects the Branda WordPress plugin through a privilege escalation flaw enabling account takeover. Patch availability stands at 0%, requiring organizations to implement compensating controls until vendor fixes become available.
Immediate action: Organizations running Gladinet CentreStack/Triofox, Apple products, ASUS systems with Live Update, Digiever DS-2105 Pro, or MongoDB Server should prioritize monitoring for exploitation indicators on these actively targeted platforms. With 0% patch availability for yesterday's disclosures, implement network segmentation and access controls as interim mitigations while monitoring vendor security advisories.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.