LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-10035: Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability

RBRecent Breaches Vulnerability Intelligence·Sep 29, 2025
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Oct 20, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-10035 to its Known Exploited Vulnerabilities catalog on Sep 29, 2025, with a federal patch deadline of Oct 20, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Fortra GoAnywhere MFT contains a deserialization of untrusted data vulnerability allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object…

CVE-2025-10035 is a deserialization of untrusted data vulnerability in Fortra GoAnywhere MFT, a managed file transfer product. An attacker who can supply a validly forged license response signature may cause the software to deserialize an arbitrary object under their control, which can lead to command injection. This matters because successful exploitation can give an attacker a foothold on the host running GoAnywhere MFT, and the vulnerability is known to have been used in ransomware operations. Defenders should treat exposed or internet-facing instances as high priority and confirm all details against the vendor advisory.

How it works

The core weakness is CWE-502 (deserialization of untrusted data), which can chain into CWE-77 (command injection). In this case, the product processes license-related responses. If an attacker forges a license response that carries a valid signature, the application may deserialize an object the attacker controls. Deserialization of untrusted data is a well-known class of flaw: the runtime reconstructs objects from attacker-supplied data, and if those objects include gadgets or callbacks that execute system commands, the result is remote code execution or command injection on the server. Public detail on the exact object graph or signature-forging method is limited; treat the CISA description as the authoritative high-level summary and verify technical mechanics only against Fortra’s advisory. No exploit code or version-specific trigger details are provided here.

Am I affected? How to find it in your systems

GoAnywhere MFT is typically deployed as an on-premises or cloud-hosted managed file transfer gateway used for secure file exchange with partners, customers, or internal systems. It often sits at the network edge or in a DMZ and may be reachable over HTTPS or other transfer protocols.

If you cannot confirm the version or patch status, assume the instance is potentially vulnerable until proven otherwise against the advisory.

How to remediate

Patch first. Apply the mitigations and updates published by Fortra for CVE-2025-10035 exactly as described in the vendor instructions. CISA’s required action is to apply those mitigations, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. After patching, restart services as directed, re-validate license and configuration state, and re-scan to confirm the vulnerability is no longer reported. Document the change and retain evidence of the update for audit and incident-response purposes. Hardening steps that reduce risk for this class of flaw include restricting which accounts can perform license or administrative operations, ensuring the service runs with least privilege, and disabling any unused license or update channels if the vendor permits it.

If you can't patch immediately

Until the vendor update can be applied, reduce the attack surface with compensating controls:

These measures lower risk but do not eliminate it; schedule the official patch as soon as operationally feasible.

If your data may have been exposed

Actively exploited vulnerabilities, especially those known to be used by ransomware operators, frequently lead to data theft or encryption. If you discover evidence of exploitation or cannot rule it out, treat the incident as a potential breach: isolate affected systems, preserve logs and disk images, and engage your incident-response process. Review file-transfer logs for unauthorized exfiltration and check whether credentials or partner data stored in or processed by GoAnywhere MFT may have been accessed. As a quick personal check, you can run a free exposure scan of your email address against known breach data sets to see whether related accounts appear in public dumps. Continue to follow the vendor advisory and CISA guidance for any additional recovery steps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedFortra · GoAnywhere MFT
WeaknessCWE-502
Added to CISA KEVSep 29, 2025
Federal patch deadlineOct 20, 2025
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities