Deserialization Vulnerability in Fortra's GoAnywhere MFT
CVE-2025-10035

10CRITICAL

Key Information:

Vendor

Fortra

Vendor
CVE Published:
18 September 2025

What is CVE-2025-10035?

A deserialization vulnerability exists in the License Servlet of Fortra's GoAnywhere MFT. This flaw permits an attacker with a forged license response signature to deserialize a potentially arbitrary actor-controlled object, which may lead to command injection exploits.

Affected Version(s)

GoAnywhere MFT Linux 0 <= 7.8.3

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-10035 : Deserialization Vulnerability in Fortra's GoAnywhere MFT