UNKNOWNKNOWN EXPLOITEDRANSOMWARE: KNOWN
CVE-2025-10035
Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability
Summary
Fortra GoAnywhere MFT contains a deserialization of untrusted data vulnerability allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.
References
Includes data from the CISA Known Exploited Vulnerabilities catalog.
CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.