CVE-2025-10035

A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.

  • Published Sep 18, 2025
  • CVSS 9.8 critical
  • 99.8% chance of exploitation in the next 30 days (EPSS)
  • In CISA's Known Exploited Vulnerabilities catalog

Affected software

In the news

CVE-2025-10035 at the National Vulnerability Database