Junglewise Threat Intelligence

CVE-2025-10035: Fortra GoAnywhere MFT deserialization in License Servlet

CVE-2025-10035 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2025-09-29

Technologies: Fortra GoAnywhere MFT. Vendors: Fortra.

Executive brief

Fortra GoAnywhere MFT is a managed file transfer solution used by organizations to securely share and manage data. A critical vulnerability has been identified that allows an attacker to bypass security controls and execute unauthorized commands on the server. This could lead to a total compromise of the system, including the theft of sensitive files, data destruction, or a foothold for further attacks within the corporate network. This vulnerability is reportedly being exploited in the wild.

Technical details

A deserialization vulnerability exists in the License Servlet component of Fortra GoAnywhere MFT. The flaw (CWE-502) occurs when the application processes a license response; an attacker who can provide a validly forged license response signature can trigger the deserialization of arbitrary, attacker-controlled objects. This leads to improper neutralization of special elements used in a command (CWE-77), resulting in remote command injection. The attack is reachable over the network without authentication. This vulnerability has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. Patches are available in versions 7.6.3 and 7.8.4.

Affected products

  • Fortra GoAnywhere MFT Versions up to (excluding) 7.6.3; 7.7.0 up to (excluding) 7.8.4

Timeline

  • 2025-09-18: advisory: Initial advisory published by Fortra
  • 2025-09-29: kev added: Added to CISA Known Exploited Vulnerabilities catalog
  • 2025-09-29: exploited: Confirmed exploitation in the wild per CISA KEV entry

Related threats