logo

Researchers raise alarm over maximum-severity defect in GoAnywhere file-transfer service

ID: ff984fbe-600b-52fc-adff-51cd6e4b866b

STIX ID: report--ff984fbe-600b-52fc-adff-51cd6e4b866b

Feed Name: CyberScoop

Threat Score
75/100

Date Published: 2025-09-19

Date Updated: 2026-04-21

Author: Matt Kapko

...
...

A critical deserialization vulnerability (CVE-2025-10035, CVSS 10) was disclosed in Fortra's GoAnywhere MFT that enables unauthenticated deserialization of attacker-controlled objects and potential command injection; Fortra released a patch and mitigation guidance. Researchers note the flaw is nearly identical to a 2023 zero-day abused by Clop and, while no public exploitation has been observed yet, security firms warn widespread exploitation by ransomware groups is likely given the product's broad use.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.