CVE-2025-10035
GoAnywhere MFT vulnerability analysis and mitigation

Overview

CVE-2025-10035 is a critical deserialization vulnerability in the License Servlet of Fortra's GoAnywhere Managed File Transfer (MFT) software that allows an unauthenticated remote attacker with a validly forged license response signature to deserialize arbitrary actor-controlled objects, potentially leading to command injection and full system compromise. The vulnerability affects GoAnywhere MFT versions before 7.6.3 and versions 7.7.0 through 7.8.4 (exclusive). It was first published on September 18, 2025, and was exploited as a zero-day approximately one week before public disclosure. It carries a CVSS v3.1 base score of 9.8 (Critical) (Fortra Advisory, CISA KEV).

Technical details

The root cause is improper deserialization of untrusted data (CWE-502) in the GoAnywhere MFT License Servlet, which when exploited leads to command injection (CWE-77). An attacker can forge a valid-looking license response signature and submit it to the License Servlet endpoint, causing the server to deserialize an attacker-controlled Java object. This deserialization gadget chain then enables arbitrary OS command execution on the underlying server without requiring any prior authentication or user interaction. WatchTowr Labs published a two-part technical write-up detailing the exploitation mechanics, and SonicWall's blog confirmed the deserialization-to-command-injection chain (WatchTowr Part 1, WatchTowr Part 2, SonicWall).

Impact

Successful exploitation grants an unauthenticated remote attacker complete control over the GoAnywhere MFT server, enabling arbitrary command execution, data exfiltration of all managed file transfers and credentials, lateral movement into connected systems, and ransomware deployment. Given GoAnywhere MFT's role as a managed file transfer platform handling sensitive organizational data, compromise can expose confidential files, partner data, and credentials stored or transiting the system. Threat actors have leveraged this vulnerability to deploy Medusa ransomware, resulting in large-scale data theft — including a reported 834 GB exfiltration from Comcast — and extortion demands (Microsoft Security Blog, BleepingComputer).

Exploitation steps

  1. Reconnaissance: Identify internet-facing GoAnywhere MFT instances using tools like Shodan or Censys, targeting versions before 7.6.3 or between 7.7.0 and 7.8.4. Approximately 20,000 systems were estimated to be exposed at the time of disclosure.
  2. Forge license response signature: Craft a malicious license response payload with a validly forged signature that the GoAnywhere MFT License Servlet will accept as legitimate.
  3. Submit malicious payload to License Servlet: Send an HTTP request containing the forged license response to the GoAnywhere MFT License Servlet endpoint, triggering the server-side deserialization process.
  4. Trigger deserialization gadget chain: The server deserializes the attacker-controlled object, executing a Java deserialization gadget chain that leads to OS-level command injection.
  5. Achieve remote code execution: Arbitrary commands execute as the GoAnywhere MFT service account, enabling reverse shell establishment, credential harvesting, or direct ransomware payload deployment.
  6. Post-exploitation: Storm-1175 was observed deploying Medusa ransomware, exfiltrating data, and using remote monitoring and management (RMM) tools for persistence and lateral movement within victim environments (WatchTowr Part 2, Microsoft Security Blog).

Indicators of compromise

  • Network: Unusual or unexpected HTTP/HTTPS requests to the GoAnywhere MFT License Servlet endpoint from external IP addresses; outbound connections from the GoAnywhere server to unknown external IPs or C2 infrastructure; large data transfers (exfiltration) from the MFT server.
  • Process: Unexpected child processes spawned by the GoAnywhere MFT Java process (e.g., cmd.exe, powershell.exe, bash, curl, wget); execution of RMM tools (e.g., AnyDesk, TeamViewer) not previously installed; Medusa ransomware binary execution.
  • File System: Presence of ransomware notes or encrypted files on the GoAnywhere server or connected file shares; unexpected web shells or scripts in the GoAnywhere installation directory; new scheduled tasks or services created by the GoAnywhere service account.
  • Logs: GoAnywhere MFT access logs showing unusual POST requests to the License Servlet with anomalous payload sizes; Java deserialization-related errors or stack traces in application logs; Windows Event Logs showing new process creation under the GoAnywhere service account.
  • Sigma Rule: A Sigma detection rule for CVE-2025-10035 process creation on Windows is available at detection.fyi (SOC Prime).

Mitigation and workarounds

Fortra released patched versions on September 19, 2025: upgrade to GoAnywhere MFT 7.6.3 or later (for versions prior to 7.7.0) or 7.8.4 or later (for versions 7.7.0 and above). CISA mandated that federal agencies apply mitigations by October 20, 2025 per BOD 22-01. Organizations unable to patch immediately should restrict network access to the GoAnywhere MFT License Servlet, implement egress filtering, and monitor for anomalous deserialization activity. Cloudflare released an emergency WAF rule on September 24, 2025 to provide interim protection (Fortra Advisory, CISA KEV).

Community reactions

Fortra published a full exploitation timeline in October 2025, confirming the zero-day exploitation began approximately one week before the patch was released and acknowledging unauthorized activity on GoAnywhere MFT instances (The Hacker News). Security researchers at WatchTowr Labs published detailed technical analyses in two parts, with the community on Reddit's r/netsec and r/blueteamsec actively discussing the exploitation mechanics. Microsoft's Threat Intelligence team published a detailed blog on October 6, 2025 attributing attacks to Storm-1175 and linking them to Medusa ransomware campaigns, which generated significant media coverage across BleepingComputer, SecurityWeek, The Record, and Dark Reading (Microsoft Security Blog, BleepingComputer). Security experts publicly questioned Fortra's transparency and response speed, with CyberDaily noting community criticism of the vendor's communication (CyberDaily). The vulnerability drew comparisons to the 2023 GoAnywhere MFT zero-day (CVE-2023-0669) exploited by the Clop ransomware group.

Additional resources


SourceThis report was generated using AI

Related GoAnywhere MFT vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-14362HIGH7.3
  • GoAnywhere MFT logoGoAnywhere MFT
  • cpe:2.3:a:fortra:goanywhere_managed_file_transfer
NoYesApr 21, 2026
CVE-2026-1089MEDIUM6.5
  • GoAnywhere MFT logoGoAnywhere MFT
  • cpe:2.3:a:fortra:goanywhere_managed_file_transfer
NoYesApr 21, 2026
CVE-2026-0972MEDIUM5.4
  • GoAnywhere MFT logoGoAnywhere MFT
  • cpe:2.3:a:fortra:goanywhere_managed_file_transfer
NoYesApr 21, 2026
CVE-2025-1241MEDIUM4.9
  • GoAnywhere MFT logoGoAnywhere MFT
  • cpe:2.3:a:fortra:goanywhere_managed_file_transfer
NoYesApr 21, 2026
CVE-2026-0971MEDIUM4.3
  • GoAnywhere MFT logoGoAnywhere MFT
  • cpe:2.3:a:fortra:goanywhere_managed_file_transfer
NoYesApr 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management