Skip to main content

Fortra Releases Security Update for GoAnywhere MFT

Successful exploitation could allow an attacker to inject arbitrary commands

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Successful exploitation could allow an attacker to inject arbitrary commands


Affected platforms

The following platforms are known to be affected:

Threat details

Introduction

Forta has released a security update to address a critical vulnerability in the GoAnywhere Admin Console.

  • CVE-2025-10035 - Deserialisation of Untrusted Data vulnerability - CVSSv3: 10.0

Remediation advice

Affected organisations are encouraged to review Fortra's Deserialization Vulnerability in GoAnywhere MFT's License Servlet advisory and apply relevant updates as soon as possible.



Last edited: 22 September 2025 2:48 pm