CVE-2025-10035
A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.
- Published Sep 18, 2025
- CVSS 9.8 critical
- 99.8% chance of exploitation in the next 30 days (EPSS)
- In CISA's Known Exploited Vulnerabilities catalog
Affected software
In the news
- VulnCheck Research Highlights: October 2025 VulnCheck Blog ·
- Oracle E-Business Suite CVE-2025-61882 Exploited in Extortion Attacks VulnCheck Blog ·