Fortra Security Update – 21 September 2025

Fortra has released a security update to fix a critical vulnerability in GoAnywhere MFT’s License Servlet.

The addressed vulnerability could allow the remote attacker with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.

Deserialization Vulnerability in GoAnywhere MFT’s License Servlet (CVE-2025-10035):

  • CVSS: 10
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Access
Vulnerabilities

CVE-2025-10035

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Fortra Security Advisory

References