Skip to main content

Maximum severity GoAnywhere MFT flaw exploited as zero day

  • September 26, 2025
  • 0 replies
  • 10 views

Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54

September 26, 2025 By Bill Toulas

 

Maximum severity GoAnywhere MFT flaw exploited as zero day

Hackers are actively exploiting a maximum severity vulnerability (CVE-2025-10035) in Fortra's GoAnywhere MFT that allows injecting commands remotely without authentication.

The vendor disclosed the flaw on September 18, buit the company had learned about it a week earlier, and did not share any details on how it was discovered or if it was being exploited.

CVE-2025-10035 is a deserialization vulnerability in the License Servlet of the GoAnywhere managed file transfer software that can be leveraged to inject commands by "an actor with a validly forged license response signature."

Although Fortra's advisory hasn't been updated to include any information about the vulnerabililty being used in attacks, security researchers at WatchTowr Labs say that they received "credible evidence" of Fortra GoAnywhere CVE-2025-10035 being leveraged as a zero day.

"We have been given credible evidence of in-the-wild exploitation of Fortra GoAnywhere CVE-2025-10035 dating back to September 10, 2025," reads WatchTowr's report.

 

>>Full Article<<