A vulnerability has been discovered in GoAnywhere Managed File Transfer (MFT) which could allow for Command Injection. GoAnywhere Managed File Transfer (MFT) is an enterprise-level software solution for securely automating, managing, and tracking all organizational file transfers, whether server-to-server or person-to-person. Successful exploitation of this vulnerability could allow an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.
THREAT INTELLIGENCE:
There are currently no reports of this vulnerability being exploited in the wild.
SYSTEMS AFFECTED:
-
GoAnywhere Managed File Transfer (MFT) versions prior to the latest release 7.8.4, or the Sustain Release 7.6.3
RISK:
Government:
-
Large and medium government entities: High
-
Small government entities: Medium
Businesses:
-
Large and medium business entities: High
-
Small business entities: Medium
Home users: Low
TECHNICAL SUMMARY:
A vulnerability has been discovered in GoAnywhere Managed File Transfer (MFT), which could allow for command injection. Details of the vulnerability are as follows:
Tactic: Initial Access (TA0001):
Technique: Exploit Public-Facing Application (T1190):
-
A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection. Fortra indicated to ensure that access to the GoAnywhere Admin Console is not open to the public. Exploitation of this vulnerability is highly dependent upon systems being externally exposed to the internet. (CVE-2025-10035)
Successful exploitation of this vulnerability could allow an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.
RECOMMENDATIONS:
We recommend the following actions be taken:
-
Apply appropriate updates provided by Fortra or other vendors which use this software to vulnerable systems immediately after appropriate testing. (M1051: Update Software)
-
Safeguard 7.1 : Establish and Maintain a Vulnerability Management Process: Establish and maintain a documented vulnerability management process for enterprise assets. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.
-

