The U.S. Cybersecurity and Infrastructure Safety Company (CISA) on Tuesday added a essential safety flaw impacting Gladinet CentreStack to its Recognized Exploited Vulnerabilities (KEV) catalog, citing proof of energetic exploitation within the wild.
The vulnerability, tracked as CVE-2025-30406 (CVSS rating: 9.0), considerations a case of a hard-coded cryptographic key that may very well be abused to realize distant code execution. It has been addressed in model 16.4.10315.56368 launched on April 3, 2025.
“Gladinet CentreStack accommodates a use of hard-coded cryptographic key vulnerability in the best way that the applying manages keys used for ViewState integrity verification,” CISA mentioned. “Profitable exploitation permits an attacker to forge ViewState payloads for server-side deserialization, permitting for distant code execution.”
Particularly, the shortcoming is rooted in the usage of a hard-code “machineKey” within the IIS net.config file, which permits menace actors with information of “machineKey” to serialize a payload for subsequent server-side deserialization in an effort to obtain distant code execution.

There are at the moment no particulars on how the vulnerability is being exploited, the id of the menace actors exploiting it, and who stands out as the targets of those assaults. That mentioned, an outline of the safety defect on CVE.org states that CVE-2025-30406 was exploited within the wild in March 2025, indicating its use as a zero-day.
Gladinet, in an advisory, has additionally acknowledged that “exploitation has been noticed within the wild,” urging clients to use the fixes as quickly as potential. If quick patching is just not an choice, it is suggested to rotate the machineKey worth as a brief mitigation.