Critical· 10actively exploitedofficial fix available
CVE-2025-10035
CVE-2025-10035 is a critical deserialization vulnerability in Fortra's GoAnywhere MFT that allows attackers to execute arbitrary commands via forged license signatures. It is actively exploited and requires immediate mitigation per CISA guidelines.
publishedSep 18, 2025
last modifiedAug 4, 2026
sourcesNVD · CISA-KEV
severity · cvss
10
critical · how bad it is
exploitation · epss
100%
100th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Sep 3, 2026
An official fix is available, so this entry is kept for 30 days and then removed automatically.
01
Who is affected
Users of Fortra GoAnywhere Managed File Transfer (CPE: fortra goanywhere_managed_file_transfer)
02
Real-world impact
Attackers can execute arbitrary commands on affected systems, leading to full compromise.
03
Why this severity
CVSS 10 (critical) due to high confidence, impact, and ease of exploitation via forged signatures.
04
What to do about it
official fix available
recommended steps
- 01Apply the vendor's recommended mitigations as outlined in their official advisory.
- 02For cloud services, follow CISA's BOD 22-01 guidance for mitigations.
- 03If mitigations are unavailable, discontinue use of the product immediately.
CISA KEV required action and vendor advisory
05
Timeline
- Sep 18, 2025 · Sep 18, 2025PublishedDisclosed and added to the National Vulnerability Database.
- Sep 29, 2025 · Sep 29, 2025Confirmed exploited (CISA KEV)CISA added it to the Known Exploited Vulnerabilities catalog — attackers are using it in the wild.
- Oct 20, 2025 · Oct 20, 2025CISA remediation deadlineFederal agencies are required to remediate by this date.
- Aug 4, 2026 · 2d agoAdvisory updatedThe NVD record was last revised.
- Aug 4, 2026 · 1d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
06
How it’s attacked
Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionNone needed
ScopeChanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07
References & advisories
- fortra.com/security/advisories/product…vendor advisory
- cisa.gov/known-exploited-vulnerabili…us government resource
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →