Critical CVSS 10.0 Flaw in GoAnywhere MFT Enables Remote Command Execution – Patch Now

# Critical Security Flaw Discovered in GoAnywhere File Transfer Software

Fortra has revealed a severe security vulnerability in its GoAnywhere Managed File Transfer (MFT) software that could allow cybercriminals to execute malicious commands on affected systems.

## Maximum Severity Rating

The vulnerability, designated as CVE-2025-10035, has received the highest possible severity score of 10.0 on the CVSS scale. This critical flaw exists in the License Servlet component of the software, where a deserialization vulnerability enables attackers with forged license signatures to inject arbitrary commands into the system.

## How the Attack Works

The vulnerability allows malicious actors to deserialize controlled objects through the license verification process, potentially leading to complete system compromise. However, successful exploitation requires the GoAnywhere system to be accessible from the internet, which is common for many organizations using this file transfer solution.

## Immediate Action Required

Fortra strongly recommends users update to the latest patched versions:
– **Version 7.8.4** (current release)
– **Version 7.6.3** (sustain release)

For organizations unable to patch immediately, Fortra advises restricting public access to the GoAnywhere Admin Console as a temporary protective measure.

## History of Exploitation

While no active exploitation of this new vulnerability has been reported, GoAnywhere has been a frequent target for cybercriminals. Previous vulnerabilities in the same software were exploited by ransomware groups:

– **CVE-2023-0669**: Exploited as a zero-day by ransomware actors including LockBit
– **CVE-2024-0204**: Could have allowed creation of unauthorized administrator accounts

## Expert Warning

Security researchers warn that this vulnerability is likely to be exploited soon. Ryan Dewhurst from watchTowr notes that thousands of GoAnywhere instances are exposed online, making them attractive targets for cybercriminals and advanced persistent threat (APT) groups.

## Bottom Line

Organizations using GoAnywhere MFT should treat this as an emergency security update. The combination of maximum severity rating, internet exposure, and the software’s history of being targeted makes immediate patching critical for preventing potential data breaches and ransomware attacks.

Share This Article