A critical vulnerability, CVE-2025-10035, has been reported in Fortra’s GoAnywhere Managed File Transfer (MFT) platform. The issue is a deserialization flaw in the License Servlet component that can be triggered by a forged license response signature; when exploited it allows attacker-controlled objects to be deserialized, potentially leading to command injection and full system compromise. The vulnerability has been assigned a maximum CVSSv3.1 score of 10.0. Administrators should consult the vendor advisory for exact affected versions and the vendor-supplied fixes or mitigations and apply them immediately.
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.
References:

