CRITICAL

CVE-2025-10035

Fortra Goanywhere Managed File Transfer 2025-09-18 CVSS v3.1
CVSS
9.8
KEV

Description

A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.

Summary dbcve.org

A deserialization vulnerability exists in the License Servlet of Fortra's GoAnywhere MFT. An attacker who can forge a valid license response signature can deserialize arbitrary attacker-controlled objects, potentially achieving command injection. This is a pre-authentication deserialization flaw with critical CVSS 9.8 severity.

Mitigation

Apply vendor-supplied patches or upgrade to a patched version of GoAnywhere MFT. If immediate patching is not possible, restrict network access to the License Servlet and monitor for indicators of compromise.

Weakness (CWE)

CWE-77 Command Injection
CWE-502 Deserialization of Untrusted Data

EPSS Score

99.8%
Probability of exploitation in next 30 days
100th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE