CyberSec.Space Logo
Back to CVE Browser

CVE-2025-10035

🔥 Known Exploited (CISA KEV)CRITICAL
10.0
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2025-09-18
Last Modified2026-06-17
Data SourcesNVDCISA KEV

Vulnerability Description

A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.

Affected Platforms (CPE)

📦
Fortra

Goanywhere Managed File Transfer

< 7.6.3>= 7.7.0 and < 7.8.4

References & Advisories

Related Vulnerabilities