Sploitus

CVE-2025-10035

3 known exploits for CVE-2025-10035

A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.

Affected products
Goanywhere Mft
Fortra Goanywhere Managed File Transfer
< 7.6.3, 7.8.4
Fix
Available
CVSS 3.1
10.0 CRITICAL
EPSS
99.6% (100th percentile)
Weakness
CWE-502, CWE-77
NVD status
Analyzed
Published
2025-09-18
Attack patterns
CAPEC-248
Entry point
licenseData request body
Path
/license

Fix

Upgrade to a patched version (the latest release 7.8.4, or the Sustain Release 7.6.3)

Workaround

Immediately ensure that access to the GoAnywhere Admin Console is not open to the public. Exploitation of this vulnerability is highly dependent upon systems being externally exposed to the internet.

CVE-2025-10035 at NVD
Authoritative description, scoring and affected products

3 known exploits for CVE-2025-10035

Proof-of-concept code and exploit modules indexed by Sploitus