
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-10035 is a critical deserialization vulnerability in the License Servlet of Fortra's GoAnywhere Managed File Transfer (MFT) software that allows an unauthenticated remote attacker with a validly forged license response signature to deserialize arbitrary actor-controlled objects, potentially leading to command injection and full system compromise. The vulnerability affects GoAnywhere MFT versions before 7.6.3 and versions 7.7.0 through 7.8.4 (exclusive). It was first published on September 18, 2025, and was exploited as a zero-day approximately one week before public disclosure. It carries a CVSS v3.1 base score of 9.8 (Critical) (Fortra Advisory, CISA KEV).
The root cause is improper deserialization of untrusted data (CWE-502) in the GoAnywhere MFT License Servlet, which when exploited leads to command injection (CWE-77). An attacker can forge a valid-looking license response signature and submit it to the License Servlet endpoint, causing the server to deserialize an attacker-controlled Java object. This deserialization gadget chain then enables arbitrary OS command execution on the underlying server without requiring any prior authentication or user interaction. WatchTowr Labs published a two-part technical write-up detailing the exploitation mechanics, and SonicWall's blog confirmed the deserialization-to-command-injection chain (WatchTowr Part 1, WatchTowr Part 2, SonicWall).
Successful exploitation grants an unauthenticated remote attacker complete control over the GoAnywhere MFT server, enabling arbitrary command execution, data exfiltration of all managed file transfers and credentials, lateral movement into connected systems, and ransomware deployment. Given GoAnywhere MFT's role as a managed file transfer platform handling sensitive organizational data, compromise can expose confidential files, partner data, and credentials stored or transiting the system. Threat actors have leveraged this vulnerability to deploy Medusa ransomware, resulting in large-scale data theft — including a reported 834 GB exfiltration from Comcast — and extortion demands (Microsoft Security Blog, BleepingComputer).
cmd.exe, powershell.exe, bash, curl, wget); execution of RMM tools (e.g., AnyDesk, TeamViewer) not previously installed; Medusa ransomware binary execution.Fortra released patched versions on September 19, 2025: upgrade to GoAnywhere MFT 7.6.3 or later (for versions prior to 7.7.0) or 7.8.4 or later (for versions 7.7.0 and above). CISA mandated that federal agencies apply mitigations by October 20, 2025 per BOD 22-01. Organizations unable to patch immediately should restrict network access to the GoAnywhere MFT License Servlet, implement egress filtering, and monitor for anomalous deserialization activity. Cloudflare released an emergency WAF rule on September 24, 2025 to provide interim protection (Fortra Advisory, CISA KEV).
Fortra published a full exploitation timeline in October 2025, confirming the zero-day exploitation began approximately one week before the patch was released and acknowledging unauthorized activity on GoAnywhere MFT instances (The Hacker News). Security researchers at WatchTowr Labs published detailed technical analyses in two parts, with the community on Reddit's r/netsec and r/blueteamsec actively discussing the exploitation mechanics. Microsoft's Threat Intelligence team published a detailed blog on October 6, 2025 attributing attacks to Storm-1175 and linking them to Medusa ransomware campaigns, which generated significant media coverage across BleepingComputer, SecurityWeek, The Record, and Dark Reading (Microsoft Security Blog, BleepingComputer). Security experts publicly questioned Fortra's transparency and response speed, with CyberDaily noting community criticism of the vendor's communication (CyberDaily). The vulnerability drew comparisons to the 2023 GoAnywhere MFT zero-day (CVE-2023-0669) exploited by the Clop ransomware group.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."