Fortra has released patches for a critical vulnerability in its GoAnywhere secure managed file transfer (MFT) that could be exploited for command injection.
See also: Warning: Critical vulnerability in the GoAnywhere MFT platform

GoAnywhere MFT is an enterprise application that allows organizations to automate and secure data exchange with their trading partners.
Tracked as CVE-2025-10035 (CVSS score 10), the critical bug is described as an untrusted data deserialization issue affecting the application's license servlet
According to Fortra's advisory, the flaw could be exploited by "an attacker with a validly forged license response signature to deserialize an arbitrary object controlled by the attacker, potentially leading to command injection."
Successful exploitation of the flaw, Rapid7, could allow unauthorized attackers to achieve remote code execution (RCE) on vulnerable GoAnywhere MFT instances.
See also: Popular Zero-Day vulnerabilities actively exploited in 2025

Fortra included patches for the security flaw in GoAnywhere MFT version 7.8.4 and GoAnywhere MFT Sustain version 7.6.3 and urged customers to ensure that the GoAnywhere Management Console is not publicly accessible.
Fortra also advises customers to monitor their administrator audit logs for suspicious activity and to search the logs for errors containing the string SignedObject.getObject: in the exception stack traces, which indicates exposure to the vulnerability.
However, Fortra does not report that this vulnerability was exploited in real time, and Rapid7 notes that it has not seen any public exploit code either.
See also: CISA warns of Delta Electronics vulnerabilities

In 2023, hackers associated with the infamous Cl0p ransomware exploited a zero-day vulnerability (CVE-2023-0669) in Fortra's file transfer product, created unauthorized accounts in customer environments, and stole data from dozens of organizations.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
