CVE-2025-10035
Description
A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.
Summary dbcve.org
A deserialization vulnerability exists in the License Servlet of Fortra's GoAnywhere MFT. An attacker who can forge a valid license response signature can deserialize arbitrary attacker-controlled objects, potentially achieving command injection. This is a pre-authentication deserialization flaw with critical CVSS 9.8 severity.
Mitigation
Apply vendor-supplied patches or upgrade to a patched version of GoAnywhere MFT. If immediate patching is not possible, restrict network access to the License Servlet and monitor for indicators of compromise.