Fortra has revealed a severe security vulnerability in its GoAnywhere Managed File Transfer (MFT) software that could allow cybercriminals to execute malicious commands on affected systems.
## Maximum Severity Rating
The vulnerability, designated as CVE-2025-10035, has received the highest possible severity score of 10.0 on the CVSS scale. This critical flaw exists in the License Servlet component of the software, where a deserialization vulnerability enables attackers with forged license signatures to inject arbitrary commands into the system.
## How the Attack Works
The vulnerability allows malicious actors to deserialize controlled objects through the license verification process, potentially leading to complete system compromise. However, successful exploitation requires the GoAnywhere system to be accessible from the internet, which is common for many organizations using this file transfer solution.
## Immediate Action Required
Fortra strongly recommends users update to the latest patched versions:
– **Version 7.8.4** (current release)
– **Version 7.6.3** (sustain release)
For organizations unable to patch immediately, Fortra advises restricting public access to the GoAnywhere Admin Console as a temporary protective measure.
## History of Exploitation
While no active exploitation of this new vulnerability has been reported, GoAnywhere has been a frequent target for cybercriminals. Previous vulnerabilities in the same software were exploited by ransomware groups:
– **CVE-2023-0669**: Exploited as a zero-day by ransomware actors including LockBit
– **CVE-2024-0204**: Could have allowed creation of unauthorized administrator accounts
## Expert Warning
Security researchers warn that this vulnerability is likely to be exploited soon. Ryan Dewhurst from watchTowr notes that thousands of GoAnywhere instances are exposed online, making them attractive targets for cybercriminals and advanced persistent threat (APT) groups.
## Bottom Line
Organizations using GoAnywhere MFT should treat this as an emergency security update. The combination of maximum severity rating, internet exposure, and the software’s history of being targeted makes immediate patching critical for preventing potential data breaches and ransomware attacks.
