Back to overview

CVE-2025-10035

CRITICAL KEV CISA Exploitation: ACTIVE Ransomware noto
10.0
CVSS 3.1
Description
A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.

Metadata

CVE ID
CVE-2025-10035
State
PUBLISHED
Assigner
Fortra
Reserved
2025-09-05 16:43 UTC
Published
2025-09-18 22:01 UTC
Last updated
2026-02-26 17:48 UTC
Primary CWE
CWE-77
CWE-77 Improper Neutralization of Special Elements used in a…
Vendor / Product
Fortra / GoAnywhere MFT
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
ACTIVE
Automatable
yes
Tech. Impact
total
CISA Known Exploited Vulnerability
Vulnerability name
Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability
Vendor
Fortra
Product
GoAnywhere MFT
Added to KEV
2025-09-29
Due date
2025-10-20
Ransomware
Known use
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA description
Fortra GoAnywhere MFT contains a deserialization of untrusted data vulnerability allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.
Affected products (1)
VendorProductPlatformVersions
Fortra GoAnywhere MFT Linux,Windows,MacOS 0 ≤ 7.8.3
Weakness (CWE)
CWESourceDescription
CWE-502 cna CWE-502 Deserialization of Untrusted Data
CWE-77 cna CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview