← Vulnerability feed

Vulnerability record · CVE-2025-10035 · published 18 September 2025

CVE-2025-10035: Fortra GoAnywhere MFT License Servlet deserialization to command injection

Fortra · Goanywhere Managed File Transfer

The License Servlet in Fortra GoAnywhere MFT deserializes untrusted data, and an attacker who can present a validly forged license response signature can supply an arbitrary object for deserialization. That path can lead to command injection, giving remote code execution on the MFT server. Because GoAnywhere is a file transfer gateway, compromise exposes both the host and the data moving through it.

9.8 CVSS 3.1 Critical CISA KEV since 29 Sep 2025 Known ransomware use EPSS 100% · top 0.1% CWE-77 · Command injectionCWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
2References
4 Aug 2026Last modified by NVD

Description

A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 9.8, unauthenticated network reach, KEV listing with ransomware use and an EPSS near 1.0 make this an urgent patch-first issue.

What it is

The License Servlet in Fortra GoAnywhere MFT deserializes untrusted data, and an attacker who can present a validly forged license response signature can supply an arbitrary object for deserialization. That path can lead to command injection, giving remote code execution on the MFT server. Because GoAnywhere is a file transfer gateway, compromise exposes both the host and the data moving through it.

Impact

An attacker gains remote code execution on the GoAnywhere MFT server, with high impact to confidentiality, integrity and availability. From there they can read or alter transferred files, harvest credentials and pivot into connected networks.

Attack surface

Reachable over the network through the License Servlet with no authentication and no user interaction, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The description adds a precondition: the actor must be able to forge a valid license response signature.

Exploitation

Listed in CISA KEV since 2025-09-29 with a 2025-10-20 remediation due date and flagged for known ransomware campaign use. EPSS is 0.99799 (99.957th percentile), indicating near-certain exploitation activity.

What to do

  • Apply the Fortra vendor fix for the License Servlet deserialization issue per advisory FI-2025-012; treat this as urgent given KEV status.
  • If patching cannot be completed by the KEV due date, follow vendor mitigations or discontinue use of the product, as CISA directs.
  • Restrict network access to the GoAnywhere administrative and license interfaces so only trusted management hosts can reach them.
  • Rotate license signing material and any credentials or keys stored on or used by the GoAnywhere host, assuming compromise.
  • Hunt for prior compromise on internet-facing GoAnywhere instances before restoring normal operations.

Detection

  • Monitor GoAnywhere logs and network traffic for requests to the License Servlet, especially from unexpected or external source addresses.
  • Alert on unexpected child processes spawned by the GoAnywhere Java process, which would indicate command injection.
  • Watch for outbound connections from the GoAnywhere host to unfamiliar destinations, consistent with post-exploitation or ransomware staging.
  • Review file system and configuration changes on the GoAnywhere server for tampering with license or servlet components.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-10035 to the Known Exploited Vulnerabilities catalog on 29 September 2025 as "Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 20 October 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-10035 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.2CVE-2023-0669Fortra GoAnywhere MFT pre-auth deserialization command injectionFortra GoAnywhere MFT deserializes an attacker-controlled object in the License Response Servlet, allowing command injection before authentication. T…KEVEPSS 100%analysed9.8CVE-2024-0204Fortra GoAnywhere MFT authentication bypass in admin portalGoAnywhere MFT before 7.4.1 contains an authentication bypass (CWE-425, forced browsing) in the administration portal that lets an unauthenticated us…EPSS 95%analysed7.3CVE-2025-14362Fortra goanywhere managed file transfer improper restriction of authentication attempts vulnerabilityThe login limit is not enforced on the SFTP service of Fortra's GoAnywhere MFT prior to 7.10.0 if the Web User attempting to be logged in to is confi…EPSS 0.19%6.5CVE-2026-1089Fortra goanywhere managed file transfer injection vulnerabilityUser‑Controlled HTTP Header in Fortra's GoAnywhere MFT prior to version 7.10.0 allows attackers to trigger a DNS lookup, as well as DNS Rebinding and…EPSS 0.23%6.5CVE-2024-25157Fortra goanywhere managed file transfer improper authentication vulnerabilityAn authentication bypass vulnerability in GoAnywhere MFT prior to 7.6.0 allows Admin Users with access to the Agent Console to circumvent some permis…EPSS 0.50%6.5CVE-2024-25156Fortra goanywhere managed file transfer path traversal vulnerabilityA path traversal vulnerability exists in GoAnywhere MFT prior to 7.4.2 which allows attackers to circumvent endpoint-specific permission checks in th…EPSS 0.39%5.4CVE-2026-0972Fortra goanywhere managed file transfer injection vulnerabilityHTML injection is possible in system generated emails in Fortra's GoAnywhere MFT prior to 7.10.0. Note: The title, details, and description of this C…EPSS 0.16%5.4CVE-2024-11922Fortra goanywhere managed file transfer cross-site scripting vulnerabilityMissing input validation in certain features of the Web Client of Fortra's GoAnywhere prior to version 7.8.0 allows an attacker with permission to tr…EPSS 0.23%

Source: NIST National Vulnerability Database (record CVE-2025-10035), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.