A Vulnerability in GoAnywhere Managed File Transfer (MFT) Could Allow for Command Injection
ID: 7e41ae0e-2111-5551-856d-f1b59becffd4
STIX ID: report--7e41ae0e-2111-5551-856d-f1b59becffd4
Feed Name: CISecurity.org Advisories
Threat Score
A deserialization vulnerability (CVE-2025-10035) in Fortra's GoAnywhere MFT License Servlet can allow an attacker with a validly forged license response signature to deserialize actor-controlled objects and potentially achieve command injection; exploitation requires the Admin Console to be publicly accessible, so Fortra recommends ensuring it is not exposed to the internet.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
