CVE-2025-10035: Fortra GoAnywhere MFT Deserialization of Untrusted Data
Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability. Fortra GoAnywhere MFT contains a deserialization of untrusted data vulnerability allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.
- CISA KEV-listed (remediation due 2025-10-20)
- used in ransomware campaigns
- EPSS 99.6% (99.9% percentile)
- CVSS 10 critical