CVE-2025-10035: Fortra GoAnywhere MFT Deserialization of Untrusted Data

Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability. Fortra GoAnywhere MFT contains a deserialization of untrusted data vulnerability allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.

Detection rules

Browse the CVE database

Read the full analysis on IntelFusions