GoAnywhere Managed File Transfer (MFT) Deserialization Vulnerability (CVE-2025-10035)

Fortra released security updates for a critical severity vulnerability impacting GoAnywhere MFT’s License Servlet. Tracked as CVE-2025-10035, the vulnerability has a CVSS score of 10. Successful exploitation of the vulnerability may allow an attacker to achieve unauthenticated remote code execution. CISA acknowledged the vulnerability’s active exploitation by adding it to its Known Exploited Vulnerabilities Catalog and … Continue reading “GoAnywhere Managed File Transfer (MFT) Deserialization Vulnerability (CVE-2025-10035)”