Deserialization Vulnerability in Fortra's GoAnywhere MFT
CVE-2025-10035
10CRITICAL
What is CVE-2025-10035?
A deserialization vulnerability exists in the License Servlet of Fortra's GoAnywhere MFT. This flaw permits an attacker with a forged license response signature to deserialize a potentially arbitrary actor-controlled object, which may lead to command injection exploits.
Affected Version(s)
GoAnywhere MFT Linux 0 <= 7.8.3