Skip to content

CVE-2025-30406

CVE

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
November 6, 2025
Last Seen
December 19, 2025
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

The Clop ransomware group is conducting a data extortion campaign against Gladinet CentreStack file servers. This attack exploits multiple security vulnerabilities in CentreStack and its related product, Triofox, affecting businesses that rely on these file transfer solutions.

Hackers are exploiting a cryptographic vulnerability in Gladinet's CentreStack and Triofox products, which allows for remote code execution. The flaw involves hardcoded cryptographic keys in the AES implementation, enabling unauthorized access to sensitive files. Gladinet has advised customers to up...

The Washington Post has confirmed a data breach affecting nearly 10,000 current and former employees due to a cyberattack linked to vulnerabilities in Oracle's E-Business Suite. The breach, attributed to the Cl0p ransomware group, involved the theft of sensitive personal information, including Socia...

In October 2025, the Oracle E-Business Suite (EBS) zero-day vulnerability CVE-2025-61882 was exploited by the Clop ransomware gang, affecting numerous organizations including Schneider Electric, Pan American Steel, and Cox Enterprises. This vulnerability allows unauthorized access, leading to signif...

Public Exploits

Checking GitHub for proof-of-concept code…