A critical vulnerability, CVE-2025-10035, was discovered in Fortra's GoAnywhere Managed File Transfer (MFT) solution, specifically affecting the License Servlet Admin Console in versions up to 7.8.3. This flaw is a deserialization vulnerability that allows attackers to bypass signature verification by crafting a forged license response signature, enabling the deserialization of arbitrary, attacker-controlled objects. Successful exploitation can result in command injection and remote code execution (RCE) on affected systems. The vulnerability is particularly dangerous for internet-exposed instances, as exploitation does not require authentication if attackers can craft or intercept valid license responses. Fortra released a patch for the vulnerability on September 18, 2025, but did not initially disclose that it was being actively exploited. Security researchers at WatchTowr Labs later confirmed that the vulnerability had been exploited as a zero-day since at least September 10, 2025. Microsoft Threat Intelligence identified a cybercriminal group, Storm-1175, known for deploying Medusa ransomware, as actively exploiting this vulnerability in attacks against multiple organizations. The attackers used the vulnerability for initial access, then maintained persistence by abusing remote monitoring and management (RMM) tools such as SimpleHelp and MeshAgent. They conducted network reconnaissance using Netscan, performed user and system discovery, and moved laterally within compromised networks using Microsoft Remote Desktop Connection (mstsc.exe). In at least one case, the attackers deployed Rclone to facilitate data exfiltration. The Shadowserver Foundation reported monitoring over 500 GoAnywhere MFT instances exposed online, raising concerns about the potential scale of impact. Microsoft and other security experts have urged organizations to immediately patch affected systems, review license verification mechanisms, and implement additional hardening measures. Microsoft Defender provides detection and protection coverage for this threat, and organizations are advised to monitor for signs of compromise and unusual activity related to GoAnywhere MFT. The exploitation campaign highlights the ongoing risk posed by critical vulnerabilities in widely used file transfer solutions and the speed with which ransomware affiliates can weaponize such flaws. Organizations that have not yet applied the patch or reviewed their exposure are at significant risk of compromise. The incident underscores the importance of rapid vulnerability management and the need for layered security controls to detect and respond to sophisticated threat actors. Security advisories recommend not only patching but also reviewing access logs, monitoring for suspicious RMM tool usage, and restricting internet exposure of sensitive administrative interfaces. The coordinated response from vendors and the security community has been crucial in raising awareness and providing actionable guidance to mitigate the threat.

See which actors are running it and whether you're in range.
7 events from the most recent confirmed update back to the earliest known activity.
By April 6, 2026, Microsoft said recent Storm-1175 intrusions had heavily affected healthcare organizations and also impacted education, professional services, and finance in Australia, the UK, and the US. The company said the Medusa-linked group had recently exploited more than 16 vulnerabilities across 10 products, including GoAnywhere CVE-2025-10035 and SmarterMail CVE-2026-23760, showing a broader multi-product campaign.
By October 10, 2025, reporting indicated Fortra confirmed unauthorized activity had affected GoAnywhere MFT environments. This marked a direct vendor acknowledgment of malicious activity tied to the incident beyond the earlier vulnerability disclosure and patch guidance.
On October 6, 2025, Microsoft published research attributing active exploitation of CVE-2025-10035 to Storm-1175, a Medusa-linked cybercriminal group. The company described a multi-stage intrusion chain involving RMM tools, Cloudflare Tunnel, Rclone, and in at least one case Medusa ransomware deployment.
On September 29, 2025, CISA confirmed the vulnerability was being exploited in the wild by adding CVE-2025-10035 to its Known Exploited Vulnerabilities catalog. The agency also set an October 20 deadline for U.S. federal civilian agencies to remediate affected systems.
On September 18, 2025, Fortra publicly disclosed the critical GoAnywhere MFT License Servlet deserialization flaw CVE-2025-10035, rated CVSS 10.0, and released patched versions. Fortra advised customers to upgrade, restrict public exposure of the admin console, and review logs for signs of exploitation.
Microsoft said it observed related activity as early as September 11, 2025, including initial access through GoAnywhere, persistence via SimpleHelp and MeshAgent, possible web shell creation, discovery, lateral movement, and command-and-control activity. In at least one victim environment, the intrusion later led to Medusa ransomware deployment.
Microsoft and other reporting indicate exploitation of CVE-2025-10035 in Fortra GoAnywhere MFT began in the wild by at least September 10-11, 2025, before any public disclosure or patch. The activity was later linked to Storm-1175, a group associated with Medusa ransomware.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.