DNA View

⚠️ CISA Known Exploited Vulnerability

Active Threat

This vulnerability is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. Active exploitation has been observed in the wild. This poses significant risk to federal enterprises and should be prioritized for immediate patching.

CVE-2025-10035

Critical CISA KEV
Low Medium High Critical
10.0
CVSS Score
Published: Sep 18, 2025
Last Modified: Oct 24, 2025

Vulnerability Description

A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.

CVSS Metrics

Common Vulnerability Scoring System

Vector String:

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Vector
N
Attack Complexity
L
Privileges Required
N
User Interaction
N
Scope
C
Confidentiality
H
Integrity
H
Availability
H

Known Affected Software

29 configuration(s) from 1 vendor(s)

goanywhere_managed_file_transfer
Version:
7.2.0
CPE:
cpe:2.3:a:fortra:goanywhere_managed_file_transfer:7.2.0:*:*:*:*:*:*:*
goanywhere_managed_file_transfer
Version:
7.8.2
CPE:
cpe:2.3:a:fortra:goanywhere_managed_file_transfer:7.8.2:*:*:*:*:*:*:*
goanywhere_managed_file_transfer
Version:
7.5.0
CPE:
cpe:2.3:a:fortra:goanywhere_managed_file_transfer:7.5.0:*:*:*:*:*:*:*
goanywhere_managed_file_transfer
Version:
7.0.3
CPE:
cpe:2.3:a:fortra:goanywhere_managed_file_transfer:7.0.3:*:*:*:*:*:*:*
goanywhere_managed_file_transfer
Version:
7.4.0
CPE:
cpe:2.3:a:fortra:goanywhere_managed_file_transfer:7.4.0:*:*:*:*:*:*:*
goanywhere_managed_file_transfer
Version:
7.3.0
CPE:
cpe:2.3:a:fortra:goanywhere_managed_file_transfer:7.3.0:*:*:*:*:*:*:*
goanywhere_managed_file_transfer
Version:
7.3.1
CPE:
cpe:2.3:a:fortra:goanywhere_managed_file_transfer:7.3.1:*:*:*:*:*:*:*
goanywhere_managed_file_transfer
Version:
7.2.1
CPE:
cpe:2.3:a:fortra:goanywhere_managed_file_transfer:7.2.1:*:*:*:*:*:*:*
goanywhere_managed_file_transfer
Version:
7.5.1
CPE:
cpe:2.3:a:fortra:goanywhere_managed_file_transfer:7.5.1:*:*:*:*:*:*:*
goanywhere_managed_file_transfer
Version:
7.4.1
CPE:
cpe:2.3:a:fortra:goanywhere_managed_file_transfer:7.4.1:*:*:*:*:*:*:*
goanywhere_managed_file_transfer
Version:
6.0.0
CPE:
cpe:2.3:a:fortra:goanywhere_managed_file_transfer:6.0.0:*:*:*:*:*:*:*
goanywhere_managed_file_transfer
Version:
7.1.1
CPE:
cpe:2.3:a:fortra:goanywhere_managed_file_transfer:7.1.1:*:*:*:*:*:*:*
goanywhere_managed_file_transfer
Version:
7.6.1
CPE:
cpe:2.3:a:fortra:goanywhere_managed_file_transfer:7.6.1:*:*:*:*:*:*:*
goanywhere_managed_file_transfer
Version:
7.8.3
CPE:
cpe:2.3:a:fortra:goanywhere_managed_file_transfer:7.8.3:*:*:*:*:*:*:*
goanywhere_managed_file_transfer
Version:
7.1.3
CPE:
cpe:2.3:a:fortra:goanywhere_managed_file_transfer:7.1.3:*:*:*:*:*:*:*
goanywhere_managed_file_transfer
Version:
7.0.0
CPE:
cpe:2.3:a:fortra:goanywhere_managed_file_transfer:7.0.0:*:*:*:*:*:*:*
goanywhere_managed_file_transfer
Version:
7.1.0
CPE:
cpe:2.3:a:fortra:goanywhere_managed_file_transfer:7.1.0:*:*:*:*:*:*:*
goanywhere_managed_file_transfer
Version:
7.4.2
CPE:
cpe:2.3:a:fortra:goanywhere_managed_file_transfer:7.4.2:*:*:*:*:*:*:*
goanywhere_managed_file_transfer
Version:
7.6.0
CPE:
cpe:2.3:a:fortra:goanywhere_managed_file_transfer:7.6.0:*:*:*:*:*:*:*
goanywhere_managed_file_transfer
Version:
7.5.2
CPE:
cpe:2.3:a:fortra:goanywhere_managed_file_transfer:7.5.2:*:*:*:*:*:*:*
goanywhere_managed_file_transfer
Version:
7.7.0
CPE:
cpe:2.3:a:fortra:goanywhere_managed_file_transfer:7.7.0:*:*:*:*:*:*:*
goanywhere_managed_file_transfer
Version:
7.0.2
CPE:
cpe:2.3:a:fortra:goanywhere_managed_file_transfer:7.0.2:*:*:*:*:*:*:*
goanywhere_managed_file_transfer
Version:
7.7.1
CPE:
cpe:2.3:a:fortra:goanywhere_managed_file_transfer:7.7.1:*:*:*:*:*:*:*
goanywhere_managed_file_transfer
Version:
7.8.1
CPE:
cpe:2.3:a:fortra:goanywhere_managed_file_transfer:7.8.1:*:*:*:*:*:*:*
goanywhere_managed_file_transfer
Version:
7.6.2
CPE:
cpe:2.3:a:fortra:goanywhere_managed_file_transfer:7.6.2:*:*:*:*:*:*:*
goanywhere_managed_file_transfer
Version:
7.8.0
CPE:
cpe:2.3:a:fortra:goanywhere_managed_file_transfer:7.8.0:*:*:*:*:*:*:*
goanywhere_managed_file_transfer
Version:
7.5.3
CPE:
cpe:2.3:a:fortra:goanywhere_managed_file_transfer:7.5.3:*:*:*:*:*:*:*
goanywhere_managed_file_transfer
Version:
7.1.2
CPE:
cpe:2.3:a:fortra:goanywhere_managed_file_transfer:7.1.2:*:*:*:*:*:*:*
goanywhere_managed_file_transfer
Version:
7.0.1
CPE:
cpe:2.3:a:fortra:goanywhere_managed_file_transfer:7.0.1:*:*:*:*:*:*:*
This vulnerability affects 29 software configuration(s). Ensure you patch all affected systems.

Severity Details

10.0
out of 10.0
Critical

CISA KEV Status

Active Exploitation

Listed in CISA's Known Exploited Vulnerabilities catalog

Key Information

Published Date
September 18, 2025