CVE-2026-8360: Gladinet Triofox

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

Function calls to WOSCommonUtil.dll!WOSSysInfoGetDeviceInterface() in various DLLs (i.e., WOSProfileMgrModule.dll, WOSWebDavModule.dll) can return a NULL pointer (i.e., when no user is logged into the Triofox Server Agent Management Console). The returned NULL pointer is not checked before being dereferenced.

Affected products

  • Gladinet Triofox: before 17.3.10565.57509 (fixed in 17.3.10565.57509)

Published 2026-05-27. Last modified 2026-06-17.