CVE-2025-10035

9.5 CISA KEV

Fortra · GoAnywhere MFT

A deserialization vulnerability in the License Servlet of Fortra GoAnywhere MFT allows remote, unauthenticated attackers to execute arbitrary commands via forged license response signatures.

Executive summary

A critical deserialization vulnerability in Fortra GoAnywhere MFT is currently being exploited in the wild, posing a severe risk of remote code execution.

Vulnerability

This flaw involves the improper deserialization of untrusted data within the License Servlet, which permits an unauthenticated attacker to inject malicious objects and achieve remote command execution on the host system.

Business impact

The exploitation of this vulnerability allows for total system compromise, including unauthorized data exfiltration, the installation of ransomware, and complete loss of server integrity. Given the CVSS score of 9.5 and confirmed active exploitation in the wild, this vulnerability represents an immediate and extreme threat to organizational operations and data security.

Remediation

Immediate Action: Upgrade to the latest release version 7.8.4 or the Sustain Release version 7.6.3 immediately.

Proactive Monitoring: Monitor server logs for suspicious traffic directed at the License Servlet and investigate any unauthorized modification of system configuration files or unexpected child processes.

Compensating Controls: Deploy Web Application Firewall rules to block requests containing anomalous license response signatures or traffic patterns targeting the License Servlet until patches can be applied.

Exploitation status

Public Exploit Available: Yes — multiple public proof-of-concept repositories are available on GitHub.

Analyst recommendation

Due to the critical severity and confirmed active exploitation of this vulnerability, organizations must prioritize the immediate deployment of the vendor-provided patches. Failure to remediate this issue exposes the environment to significant risk of ransomware infection and total system compromise. If patching is not immediately feasible, the affected service should be isolated from the network to prevent unauthorized access.

More Fortra CVEs

History

  1. Disclosed CVE record published
  2. Published in the daily brief critical section
  3. Published in the daily brief critical section
  4. Published in the daily brief critical section
  5. Published in the daily brief kev section
  6. Published in the daily brief kev section
  7. Published in the daily brief kev section
  8. Published in the daily brief kev section
  9. Published in the daily brief kev section
  10. Published in the daily brief kev section
  11. Published in the daily brief kev section
  12. Published in the daily brief kev section
  13. Published in the daily brief kev section
  14. Published in the daily brief kev section
  15. Published in the daily brief kev section
  16. Published in the daily brief kev section
  17. Published in the daily brief kev section
  18. Published in the daily brief kev section
  19. Published in the daily brief kev section
  20. Published in the daily brief kev section
  21. Published in the daily brief kev section
  22. Published in the daily brief kev section
  23. Published in the daily brief kev section
  24. Published in the daily brief kev section
  25. Look Back published
  26. Analyst report written
  27. Fix documented per CVE record

Sources