CISA orders federal gov to patch critical Fortra file transfer bug
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-0669 | Pre-Authentication Deserialization RCE in Fortra GoAnywhere MFT Fortra (formerly HelpSystems) GoAnywhere MFT is vulnerable to pre-authentication remote code execution (CWE-502) in the License Response Servlet, which deserializes an attacker-controlled object without validating it. An unauthenticated attacker who can reach the exposed administrative interface can send a crafted serialized object to the servlet and trigger code execution on the server. Successful exploitation gives the attacker the ability to run arbitrary code in the context of the application, which has been leveraged for ransomware operations. All organizations running GoAnywhere MFT with the affected component reachable by untrusted networks are in scope. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-02-10, ransomware use is confirmed, and EPSS puts the 30-day exploitation probability at 100%. Do: Apply the vendor's updates for GoAnywhere MFT immediately, per Fortra's instructions, as required by the CISA KEV catalog. Until patched, restrict or block untrusted/internet access to the administrative interface hosting the License Response Servlet, and review logs for signs of exploitation given confirmed in-the-wild and ransomware use. | 7.2 | 100% | KEV ransomware PoC ×3 |
| moderate≈1,000–10,000 internet-exposed GoAnywhere MFT instances (public internet scans of the exposed administrative interface) | |
| CVE-2025-10035 | Deserialization Flaw in Fortra GoAnywhere MFT License Servlet Enables RCE CVE-2025-10035 is a critical (CVSS 9.8) deserialization-of-untrusted-data flaw (CWE-502) in the License Servlet of Fortra GoAnywhere Managed File Transfer (MFT). It is triggered when the servlet processes a license response carrying a validly forged signature, causing it to deserialize an arbitrary attacker-controlled object; the CVSS vector indicates the attack is network-based and requires no privileges or user interaction. Successful exploitation can lead to command injection (CWE-77), effectively giving an attacker command execution on the MFT server and access to the files and credentials that flow through it. Any organization running GoAnywhere MFT, which is commonly deployed as a central file-transfer hub, is affected, although specific affected/fixed version ranges are not provided in the available data. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV catalog on 2025-09-29 with known ransomware use, Microsoft attributes attacks to the Storm-1175 ransomware affiliate (Medusa, now reportedly replaced by StormEncryptor), and EPSS assigns a 99.8% probability of exploitation within 30 days. Do: Apply mitigations or patches per Fortra's vendor instructions immediately, as this is a KEV entry carrying BOD 22-01 requirements for federal agencies (patch or discontinue use if mitigations are unavailable). Because a ransomware affiliate (Storm-1175, using Medusa/StormEncryptor) is actively exploiting it, hunt for compromise: review License Servlet traffic and logs for forged license responses, check for unexpected processes or new accounts, and look for signs of lateral movement. Until patched, restrict or remove internet exposure of GoAnywhere MFT admin and license interfaces. | 9.8 | 100% | KEV ransomware |
| moderatelow thousands of internet-exposed GoAnywhere MFT instances (estimate) |
Full article678 words · extracted from therecord.media · click to collapse
All federal civilian agencies have been ordered to patch a vulnerability affecting a widely-used file transfer tool that some researchers believe is being exploited by hackers. The Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-10035 — a critical vulnerability in Fortra's GoAnywhere MFT solution — to its Known Exploited Vulnerabilities list Monday. Federal civilian agencies have until October 20 to patch it. The vulnerability carries a severity score of 10 out of 10 and has caused alarm among cybersecurity experts who have criticized Fortra for not saying whether it has seen the bug being exploited. In comments to Recorded Future News over the past week, Fortra would not confirm industry reports that CVE-2025-10035 has already been used in attacks. A spokesperson for the company said the issue was first discovered on September 11 when Fortra “identified that GoAnywhere customers with an Admin Console accessible over the internet could be vulnerable to unauthorized third-party exposure.” “We immediately developed a patch and offered customers mitigation guidance to help resolve the issue,” the company said. “Customers should review configurations immediately and remove public access from the Admin Console. Our investigation is ongoing. We will provide further updates as appropriate." In follow-up comments this week, Fortra officials said CVE-2025-10035 is “primarily relevant to organizations with a GoAnywhere admin console exposed to the internet.” The company added that it has continued “to provide direct updates and support” to customers. Alongside CVE-2025-10035, CISA added multiple vulnerabilities to the KEV list on Monday, including issues affecting tools from Sudo, Libraesva and Cisco. Cybersecurity firm watchTowr published a lengthy report on CVE-2025-10035 and explained that there are indications that it is currently being exploited. Fortra’s advisory “is quietly hinting at real-world exploitation without explicitly saying it,” watchTowr researchers said. After releasing an initial advisory, watchTowr said it was given credible evidence showing the vulnerability was being actively exploited in the wild as early as September 10. “This is not ‘just’ a CVSS 10.0 flaw in a solution long favored by APT groups and ransomware operators — it is a vulnerability that has been actively exploited in the wild since at least September 10, 2025,” said watchTowr CEO Benjamin Harris. Harris did not have more information on who was behind the exploitation or how many victims may be vulnerable to the bug, estimating that likely thousands of internet-facing file transfer systems are at risk. There are still big questions to be answered about how hackers are exploiting the bug, according to Harris. His team is still unclear on how exploitation of this vulnerability is possible “unless a few very scary scenarios have played out.”. “We continue to be confused as to why Fortra is not advising customers of what appears to be clear evidence of in-the-wild exploitation since at least September 10th,” Harris said. “CISA’s addition of these vulnerabilities to the exclusive [Known Exploited Vulnerabilities] list only adds to this confusion. We urge Fortra to share their viewpoint and would encourage customers to ask Fortra what they should be doing with regards to patching cycles. Is this urgent, or can it wait until Christmas?” Other watchTowr experts noted that the vulnerability resembles CVE-2023-0669 — another GoAnywhere vulnerability that was exploited widely by multiple ransomware gangs in 2023. The Clop ransomware gang breached more than 130 organizations in 2023 by abusing the GoAnywhere vulnerability, stealing information from large companies like Hitachi, Rubrik, Rio Tinto, Community Health Systems and more. The governments of Toronto and Tasmania were affected by the incident alongside corporate giants like Proctor & Gamble, Virgin and several large banks. Over the last five years, cybercriminal gangs have earned millions of dollars in ransoms by exploiting vulnerabilities in file transfer tools like GoAnywhere. ‘Can it wait till Christmas?’
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/cisa-orders-federal-gov-patch-fortra-bug