CVE-2025-10035
KEV · ransomware Critical · CVSS 10.0- CVSS
- 10.0
- nvd
- EPSS
- —
- KEV
- Listed
- ransomware
- Class
- other
- CWE-77, CWE-502, CWE-77, CWE-502
Description
A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.
References
Status: profiled · ingested 2026-08-04T06:00:54.000Z