THREAT OPS › CVEs › CVE-2025-10035
CVE-2025-10035 — Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability
Fortra GoAnywhere MFT contains a deserialization of untrusted data vulnerability allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.
Vulnerability details
- Affected productsGoAnywhere MFT
- KEV remediation due2025-10-20
Related reporting
- [NVD] CVE-2025-10035 (CRITICAL 10.0) — A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.nvd
- You’re Not Supposed To ShareFile With Everyone (Progress ShareFile Pre-Auth RCE Chain CVE-2026-2699 & CVE-2026-2701)watchtowr