Fortra released security updates for GoAnywhere MFT to fix CVE-2025-10035, a critical deserialization flaw in the product's License Servlet that can let a remote, unauthenticated attacker inject commands and take full control of vulnerable systems. The issue carries a CVSS v3.1 score of 10.0 and affects 7.8.x before 7.8.4 and 7.6.x before Sustain Release 7.6.3, with internet-exposed administrative consoles facing the highest risk.
CSIRT.SK reported the vulnerability is actively exploited and may have been abused since at least 2025-09-10. Defenders were urged to upgrade immediately, restrict administrative access through firewall rules or VPNs, and review Admin Audit and application logs for indicators of compromise, including errors containing SignedObject.getObject.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
Public reporting described CVE-2025-10035 as a critical deserialization vulnerability in GoAnywhere MFT's License Servlet with a CVSS v3.1 score of 10.0. The issue was noted as actively exploited, with guidance to upgrade immediately and restrict administrative console exposure.
Fortra released security updates to address CVE-2025-10035, a critical vulnerability in the GoAnywhere MFT License Servlet. The fixes cover affected 7.8.x versions before 7.8.4 and 7.6.x versions before Sustain Release 7.6.3.
CSIRT.SK reported that the critical deserialization flaw in GoAnywhere MFT had been exploited in the wild since at least September 10, 2025. The vulnerability affects the License Servlet and can allow unauthenticated remote command injection and full system compromise.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.