CVE-2025-10035
Fortra GoAnywhere MFT, goanywhere managed file transfer
A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.
- CVSS
- 9.8
- EPSS
- 99.6% 99.9% percentile
- CISA KEV
- Listed
- Published
- 2025.09.19