CVE-2025-10035

Published Sep 18, 2025

Last updated a day ago

CVSS critical 10.0
Fortra
GoAnywhere

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-10035 is a deserialization vulnerability found in the License Servlet of Fortra's GoAnywhere MFT. It allows an attacker with a validly forged license response signature to deserialize an arbitrary, attacker-controlled object. This could potentially lead to command injection. To remediate this vulnerability, it is recommended to update GoAnywhere MFT to version 7.8.4. It is also advised to ensure that access to the GoAnywhere Admin Console is not open to the public, as exploitation of this vulnerability is highly dependent on systems being externally exposed to the internet.

Description
A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.
Source
df4dee71-de3a-4139-9588-11b62fe6c0ff
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
10
Impact score
6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

df4dee71-de3a-4139-9588-11b62fe6c0ff
CWE-77

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

28

  1. Fortra Issues Critical Alert for GoAnywhere MFT Vulnerability https://t.co/qCfzgVvpbO #cve-2025-10035 #FortraSecurityAlert #GoanywhereMft #ManagedFileTransfer

    @wizconsults

    20 Sept 2025

    15 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Parche crítico para la vulnerabilidad en GoAnywhere MFT (CVE-2025-10035 - CVSS 10) https://t.co/DlsJguSsgF

    @matarturo

    20 Sept 2025

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 19/09/2025 🚨 Max-severity CVE-2025-10035 in Fortra GoAnywhere allows command injection. Systems exposed to the Internet are at high risk. Patch now to protect your environment! Source: https://t.co/olvrNSt6Xi

    @kernyx64

    20 Sept 2025

    44 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Fortra Releases Critical Patch for CVSS 10.0 GoAnywhere MFT Vulnerability (CVE-2025-10035) https://t.co/1GeEL5HW6a #patchmanagement

    @eyalestrin

    20 Sept 2025

    24 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Fortra Patches Critical CVSS 10.0 Flaw in GoAnywhere MFT (CVE-2025-10035) #CyberSecurity #Fortra #GoAnywhere #Vulnerability #CVE2025 #PatchUpdate #DataSecurity #Ransomware #InfoSec #NetworkSecurity https://t.co/xEgl2M0Sh8

    @cyashadotcom

    20 Sept 2025

    15 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. FortraのGoAnywhere MFTに関する深刻な脆弱性と対策(CVE-2025-10035) https://t.co/EdS5x6FIRJ #Security #セキュリティ #ニュース

    @SecureShield_

    20 Sept 2025

    48 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Fortra patches critical CVE-2025-10035 deserialization flaw in GoAnywhere MFT, exploited by CL0P and LockBit ransomware groups. Update to v7.8.4 or v7.6.3 and limit internet access. #GoAnywhere #Ransomware #USA https://t.co/7CoL8Uk3Mu

    @TweetThreatNews

    19 Sept 2025

    156 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  8. Security Bulletin: GoAnywhere MFT License Servlet RCE – CVE-2025-10035 (CVSS 10.0) allows deserialization → remote command injection. Patch to 7.8.4 or 7.6.3 now. Publicly exposed Admin Consoles are high-risk. #ThreatIntel #RedLeggCTI #GoAnywhere https://t.co/Sguk1dRL2f

    @RedLegg

    19 Sept 2025

    66 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. 🐛 New GoAnywhere MFT vulnerability with CVSS score 10 (CVE-2025-10035), there are 90K+ internet facing MFT servers. Similar flaw were exploited by Cl0p RaaS in 2023. We are going to see more Ransomware victims soon, patch now (7.8.4 / 7.6.3) https://t.co/TsAvA2ygAE https://t.c

    @WhichbufferArda

    19 Sept 2025

    1090 Impressions

    0 Retweets

    7 Likes

    4 Bookmarks

    0 Replies

    0 Quotes

  10. 🐛 New GoAnywhere MFT vulnerability with CVSS score 10 (CVE-2025-10035) exposes 90K+ servers. Similar flaw were exploited by Cl0p RaaS in 2023. We are going to see more Ransomware victims soon, patch now (7.8.4 / 7.6.3) https://t.co/TsAvA2ygAE https://t.co/C16d0Dd19x

    @WhichbufferArda

    19 Sept 2025

    61 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. Fortra patches critical CVSS 10.0 flaw (CVE-2025-10035) in GoAnywhere MFT allowing command execution via forged license responses. Exploitation requires public internet exposure. Previous exploits linked to ransomware. #GoAnywhere #Vulnerability #USA https://t.co/EVeLwIBWn0

    @TweetThreatNews

    19 Sept 2025

    121 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. 🚨 CVE ALERT: Fortra GoAnywhere MFT Flaw ⚡️ ⚠️ Threat: CVE-2025-10035 → remote command injection 💻 📌 Impact: Exposed Admin Consoles & file transfer servers at risk 🛡️ Action: Patch ASAP → v7.8.4 / v7.6.3 ✅ or block internet access 🌐 Critical vu

    @Newtalics

    19 Sept 2025

    67 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  13. Fortra fixes a critical deserialization flaw (CVE-2025-10035) in GoAnywhere MFT’s License Servlet allowing remote command injection, targeting exposed Admin Consoles. Exploitation not yet confirmed. #GoAnywhere #RemoteInjection #USA https://t.co/MMkvo7np0a

    @TweetThreatNews

    19 Sept 2025

    122 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. 🚨 A CVSS score of 10.0?! The recent CVE-2025-10035 vulnerability in GoAnywhere MFT is a ticking time bomb. Remote command execution is no joke. 🔥 #CyberSecurity #Vulnerability https://t.co/xGGJopQ3xN

    @Cyb3r_5wift

    19 Sept 2025

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. 🚨 On 9/18/2025, #Fortra published an advisory for CVE-2025-10035, a new vulnerability affecting GoAnywhere MFT. The vulnerability allows an attacker to achieve unauthenticated remote code execution. More details & mitigation guidance in a new blog: https://t.co/BMvNUQgdl8

    @rapid7

    19 Sept 2025

    1225 Impressions

    1 Retweet

    6 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. At least 2 major banks are having issues I believe are related to CVE-2025-10035 either offensively or defensively. Both were prior Clop victims The temporary inconvenience is 12 hrs + https://t.co/6g4hlMh4TC

    @AlvieriD

    19 Sept 2025

    862 Impressions

    1 Retweet

    11 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  17. Parche crítico para la vulnerabilidad en GoAnywhere MFT (CVE-2025-10035 - CVSS 10) https://t.co/meYv2til0T

    @SeguInfo

    19 Sept 2025

    838 Impressions

    2 Retweets

    5 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  18. Fortra patched a critical CVSS 10.0 GoAnywhere MFT vulnerability (CVE-2025-10035) allowing arbitrary command execution. Urgent updates needed! 🚨 https://t.co/0IWGAagdtO #Fortra #GoAnywhereMFT #Cybersecurity #CVE202510035 #SecurityPatch

    @0xT3chn0m4nc3r

    19 Sept 2025

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. 🚨 Urgent: Critical flaw (CVE-2025-10035) in GoAnywhere MFT allows full server takeover. Patch immediately or restrict admin console access. Ransomware groups are likely to exploit this. https://t.co/q8dolI845S

    @RedTeamNewsBlog

    19 Sept 2025

    64 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. 🚨 Fortra GoAnywhere MFT: CVSS 10 (CVE-2025-10035) lets attackers run commands via forged license response. Thousands exposed; same admin path as the 2023 LockBit-hit bug—weaponization likely. Details → https://t.co/Nl5zL3izjS... https://t.co/cRrlQdnDv9

    @IT_news_for_all

    19 Sept 2025

    68 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. 🚨 Fortra GoAnywhere MFT: CVSS 10 (CVE-2025-10035) lets attackers run commands via forged license response. Thousands exposed; same admin path as the 2023 LockBit-hit bug—weaponization likely. Details → https://t.co/hcLoafW4fm Patch 7.8.4/7.6.3; restrict Admin Console.

    @TheHackersNews

    19 Sept 2025

    8738 Impressions

    16 Retweets

    38 Likes

    9 Bookmarks

    1 Reply

    0 Quotes

  22. CVE-2025-10035 A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an a… https://t.co/g0SYu9IIgT

    @CVEnew

    19 Sept 2025

    140 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. ⚠️⚠️ CVE-2025-10035 (CVSS 10): Critical Deserialization Flaw in GoAnywhere MFT Exposes Enterprises to Remote Exploitation 🎯19.7k+ Results are found on the https://t.co/pb16tGYaKe nearly year. 🔗FOFA Link: https://t.co/stA2GjzML0 FOFA Query:app="GoAnywhere-MFT" 🔖Re

    @fofabot

    19 Sept 2025

    888 Impressions

    0 Retweets

    14 Likes

    5 Bookmarks

    0 Replies

    0 Quotes

  24. 🚨🚨CVE-2025-10035 (CVSS 10): Fortra's GoAnywhere MFT is UNDER ATTACK! A deserialization vulnerability in the License Servlet lets attackers with a forged license response signature deserialize any object, potentially leading to remote command injection. Search by vul.cve h

    @zoomeye_team

    19 Sept 2025

    991 Impressions

    1 Retweet

    7 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  25. 🚨Alert🚨: CVE-2025-10035 (CVSS 10): Critical Deserialization Flaw in GoAnywhere MFT Exposes Enterprises to Remote Exploitation 📊142K Services are found on the https://t.co/ysWb28BTvF yearly. 🔗Hunter Link:https://t.co/PP97Szat0P 👇Query HUNTER : https://t.co/nmaxj6dPL

    @HunterMapping

    19 Sept 2025

    2664 Impressions

    8 Retweets

    49 Likes

    15 Bookmarks

    0 Replies

    0 Quotes

  26. 🚨 CVE-2025-10035: CRITICAL RCE in Fortra GoAnywhere MFT! Unauthenticated attackers can exploit a deserialization flaw for command injection—full system compromise possible. Restrict access & monitor now. https://t.co/Z3wmFsy1h0... https://t.co/P5lZr65L7T

    @offseq

    19 Sept 2025

    147 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  27. [CVE-2025-10035: CRITICAL] Deserialization vulnerability in Fortra's GoAnywhere MFT License Servlet allows remote attackers to execute commands by forging license responses. #Cybersecurity#cve,CVE-2025-10035,#cybersecurity https://t.co/frCGFMcLCa https://t.co/5lpCxh10KO

    @CveFindCom

    18 Sept 2025

    136 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

References

Sources include official advisories and independent security research.