CVE-2025-10035
A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.
- Affected products
- Goanywhere Mft
- Fortra Goanywhere Managed File Transfer
- < 7.6.3, 7.8.4
- Fix
- Available
- CVSS 3.1
- 10.0 CRITICAL
- EPSS
- 99.6% (100th percentile)
- Weakness
- CWE-502, CWE-77
- NVD status
- Analyzed
- Published
- 2025-09-18
- Attack patterns
- CAPEC-248
- Entry point
- licenseData request body
- Path
- /license
Fix
Upgrade to a patched version (the latest release 7.8.4, or the Sustain Release 7.6.3)
Workaround
Immediately ensure that access to the GoAnywhere Admin Console is not open to the public. Exploitation of this vulnerability is highly dependent upon systems being externally exposed to the internet.
CVE-2025-10035 at NVD
3 known exploits for CVE-2025-10035
Proof-of-concept code and exploit modules indexed by Sploitus