**Fortra has released emergency patches for a maximum severity vulnerability that could allow attackers to execute commands remotely on GoAnywhere MFT systems.**
## The Vulnerability
GoAnywhere MFT, a popular web-based file transfer solution used by over 3,000 organizations including Fortune 500 companies, contains a critical security flaw tracked as CVE-2025-10035. The vulnerability exists in the software’s License Servlet component and stems from improper handling of untrusted data.
The flaw allows attackers with a forged license signature to inject malicious code remotely without requiring user interaction. This makes it particularly dangerous as it can be exploited through low-complexity attacks targeting internet-exposed systems.
## Discovery and Response
Fortra discovered the vulnerability during a security review conducted on September 11, 2025. The company immediately began developing patches and providing mitigation guidance to customers. However, they have not disclosed who reported the flaw or whether it has been exploited in real-world attacks.
“GoAnywhere customers with an Admin Console accessible over the internet could be vulnerable to unauthorized third-party exposure,” Fortra stated, emphasizing the need for immediate action.
## Available Fixes
Fortra has released two updated versions containing security patches:
– GoAnywhere MFT 7.8.4
– Sustain Release 7.6.3
For organizations unable to immediately update, Fortra recommends securing systems by ensuring the GoAnywhere Admin Console cannot be accessed from the internet, as exploitation heavily depends on external exposure.
## Current Risk Assessment
The Shadowserver Foundation is currently monitoring over 470 GoAnywhere MFT instances online, though it’s unclear how many remain unpatched or have exposed admin consoles. While no active exploitation has been confirmed, security experts urge immediate patching due to the software’s attractive target profile.
## Historical Context
This isn’t the first time GoAnywhere has faced serious security issues. In 2023, the Clop ransomware group exploited a different critical vulnerability (CVE-2023-0669) to breach over 130 organizations in zero-day attacks. This history makes the current vulnerability particularly concerning for the cybersecurity community.
## Recommendations
Organizations using GoAnywhere MFT should:
1. **Immediately apply the latest security patches**
2. **Remove internet access to Admin Consoles** if patching isn’t possible
3. **Review system configurations** to ensure proper security measures
4. **Monitor for suspicious activity** on file transfer systems
Given that secure file transfer solutions often handle sensitive documents, prompt action is essential to prevent potential data breaches and system compromises.
