logo

Maximum severity GoAnywhere MFT flaw exploited as zero day

ID: 24c99dec-4624-5849-8807-46b9f7b9c9e2

STIX ID: report--24c99dec-4624-5849-8807-46b9f7b9c9e2

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2025-09-26

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A critical deserialization zero-day (CVE-2025-10035) in Fortra GoAnywhere MFT is being actively exploited to achieve unauthenticated remote command execution, create a backdoor admin account (admin-go), and deploy secondary payloads including zato_be.exe and an abused SimpleHelp binary (jwunst.exe). WatchTowr Labs reports credible evidence of exploitation dating before the vendor advisory; recommended mitigations include patching to fixed versions (7.8.4 or 7.6.3), removing public exposure of the Admin Console, and searching logs for 'SignedObject.getObject'.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.