Fortra Releases Security Update for GoAnywhere MFT
Successful exploitation could allow an attacker to inject arbitrary commands
Summary
Successful exploitation could allow an attacker to inject arbitrary commands
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Forta has released a security update to address a critical vulnerability in the GoAnywhere Admin Console.
- CVE-2025-10035 - Deserialisation of Untrusted Data vulnerability - CVSSv3: 10.0
Remediation advice
Affected organisations are encouraged to review Fortra's Deserialization Vulnerability in GoAnywhere MFT's License Servlet advisory and apply relevant updates as soon as possible.
Definitive source of threat updates
Last edited: 22 September 2025 2:48 pm