ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Unpatched Fortra GoAnywhere instances at risk of full takeover (CVE-2025-10035)

criticalVulnerability exploited in the wildimportance 60CVE-2025-10035CVE-2023-0669

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-0669
Pre-Authentication Deserialization RCE in Fortra GoAnywhere MFT

Fortra (formerly HelpSystems) GoAnywhere MFT is vulnerable to pre-authentication remote code execution (CWE-502) in the License Response Servlet, which deserializes an attacker-controlled object without validating it. An unauthenticated attacker who can reach the exposed administrative interface can send a crafted serialized object to the servlet and trigger code execution on the server. Successful exploitation gives the attacker the ability to run arbitrary code in the context of the application, which has been leveraged for ransomware operations. All organizations running GoAnywhere MFT with the affected component reachable by untrusted networks are in scope. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-02-10, ransomware use is confirmed, and EPSS puts the 30-day exploitation probability at 100%.

Do: Apply the vendor's updates for GoAnywhere MFT immediately, per Fortra's instructions, as required by the CISA KEV catalog. Until patched, restrict or block untrusted/internet access to the administrative interface hosting the License Response Servlet, and review logs for signs of exploitation given confirmed in-the-wild and ransomware use.

7.2100% KEV ransomware PoC ×3
  • Fortra GoAnywhere MFT
moderate≈1,000–10,000 internet-exposed GoAnywhere MFT instances (public internet scans of the exposed administrative interface)
CVE-2025-10035
Deserialization Flaw in Fortra GoAnywhere MFT License Servlet Enables RCE

CVE-2025-10035 is a critical (CVSS 9.8) deserialization-of-untrusted-data flaw (CWE-502) in the License Servlet of Fortra GoAnywhere Managed File Transfer (MFT). It is triggered when the servlet processes a license response carrying a validly forged signature, causing it to deserialize an arbitrary attacker-controlled object; the CVSS vector indicates the attack is network-based and requires no privileges or user interaction. Successful exploitation can lead to command injection (CWE-77), effectively giving an attacker command execution on the MFT server and access to the files and credentials that flow through it. Any organization running GoAnywhere MFT, which is commonly deployed as a central file-transfer hub, is affected, although specific affected/fixed version ranges are not provided in the available data. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV catalog on 2025-09-29 with known ransomware use, Microsoft attributes attacks to the Storm-1175 ransomware affiliate (Medusa, now reportedly replaced by StormEncryptor), and EPSS assigns a 99.8% probability of exploitation within 30 days.

Do: Apply mitigations or patches per Fortra's vendor instructions immediately, as this is a KEV entry carrying BOD 22-01 requirements for federal agencies (patch or discontinue use if mitigations are unavailable). Because a ransomware affiliate (Storm-1175, using Medusa/StormEncryptor) is actively exploiting it, hunt for compromise: review License Servlet traffic and logs for forged license responses, check for unexpected processes or new accounts, and look for signs of lateral movement. Until patched, restrict or remove internet exposure of GoAnywhere MFT admin and license interfaces.

9.8100% KEV ransomware
  • Fortra GoAnywhere Managed File Transfer (MFT)
moderatelow thousands of internet-exposed GoAnywhere MFT instances (estimate)
Full article433 words · extracted from helpnetsecurity.com · click to collapse

If you’re running Fortra’s GoAnywhere managed file transfer solution and you haven’t updated to the latest available version for a while, do so now or risk getting your instance compromised via CVE-2025-10035.

Fortra GoAnywhere vulnerability CVE-2025-10035

About CVE-2025-10035

CVE-2025-10035 is a critical deserialization vulnerability in the License servlet of Fortra’s GoAnywhere MFT managed file transfer solution, which is widely used by organizations of all sizes.

The solution can be deployed on-premises, in the cloud, and in hybrid environments.

According to Fortra, the flaw “allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.”

While there’s currently no evidence that it has been or is being exploited by attackers, CVE-2025-10035 has a maximum severity CVSS score, denoting that it’s exploitable remotely over a network, without authentication and user interaction, could lead to full system compromise (and possible lateral movement), and the explot is straightforward.

But, there is a catch: the vulnerability can only be exploited by attackers who have access to the GoAnywhere administrative console of a vulnerable installation.

In early 2023, plenty of those consoles were accessible via the internet and the Cl0p ransomware gang took advantage of those and a zero-day vulnerability (CVE-2023-0669) in the same servlet to exfiltrate data of 130+ victim organizations.

The incident hopefully spurred many an organization to make sure that the admin console is not publicly accessible from the internet. (It should be accessible only from within a private company network, through VPN, or from trusted IP addresses.)

What to do?

Fortra disclosed the vulnerability late last Thursday and has urged customers to either upgrade to a patched version (v7.8.4 or Sustain Release v7.6.3) or to ensure that access to the GoAnywhere Admin Console is not open to the public (or both).

The company has also advised them to monitor their Admin Audit logs for suspicious activity and the log files for errors containing SignedObject.getObject.

“If this string is present in an exception stack trace, then the instance was likely affected by this vulnerability,” Fortra noted.

“In general, it’s also advisable to implement egress filtering and alert on large file uploads, high-volume traffic to suspicious IPs or domains, and data transfer and archive utility usage,” VulnCheck’s VP or research Caitlin Condon added.

“As always, if the vulnerability turns out to have been exploited in the wild as a zero-day — which was unclear at time of disclosure — patching alone will not eradicate adversaries from compromised systems.”

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/09/22/fortra-goanywhere-vulnerability-cve-2025-10035/