logo

A Vulnerability in GoAnywhere Managed File Transfer (MFT) Could Allow for Command Injection

ID: 7e41ae0e-2111-5551-856d-f1b59becffd4

STIX ID: report--7e41ae0e-2111-5551-856d-f1b59becffd4

Feed Name: CISecurity.org Advisories

Threat Score
65/100

Date Published: 2025-09-19

Date Updated: 2026-04-27

...
...

A deserialization vulnerability (CVE-2025-10035) in Fortra's GoAnywhere MFT License Servlet can allow an attacker with a validly forged license response signature to deserialize actor-controlled objects and potentially achieve command injection; exploitation requires the Admin Console to be publicly accessible, so Fortra recommends ensuring it is not exposed to the internet.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.