Researchers raise alarm over maximum-severity defect in GoAnywhere file-transfer service
ID: ff984fbe-600b-52fc-adff-51cd6e4b866b
STIX ID: report--ff984fbe-600b-52fc-adff-51cd6e4b866b
Feed Name: CyberScoop
A critical deserialization vulnerability (CVE-2025-10035, CVSS 10) was disclosed in Fortra's GoAnywhere MFT that enables unauthenticated deserialization of attacker-controlled objects and potential command injection; Fortra released a patch and mitigation guidance. Researchers note the flaw is nearly identical to a 2023 zero-day abused by Clop and, while no public exploitation has been observed yet, security firms warn widespread exploitation by ransomware groups is likely given the product's broad use.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
