CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2025-10035

KEV · ransomware Critical · CVSS 10.0
CVSS
10.0
nvd
EPSS
KEV
Listed
ransomware
Class
other
CWE-77, CWE-502, CWE-77, CWE-502

Description

A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.

References

Status: profiled · ingested 2026-08-04T06:00:54.000Z