Fortra has issued a warning about a max severity flaw in its GoAnywhere MFT License Servlet. The vulnerability allows remote command injection via a forged license response. It poses a serious risk to organizations that leave their Admin Console publicly accessible.

What the Flaw Is

The vulnerability, tracked as CVE-2025-10035, stems from deserialization of untrusted data. Attackers who forge a license response signature can deserialize an object they control. In effect, they can execute commands on the affected server. Fortra discovered the flaw during a security check on September 11, 2025. They found that GoAnywhere customers with the Admin Console exposed to the internet were vulnerable. Fortra then developed and released a patch.

What Fortra Did

Fortra responded quickly. They released fixes in GoAnywhere MFT version 7.8.4 and Sustain Release 7.6.3. If upgrading immediately proves difficult, Fortra advises administrators to ensure the Admin Console is not publicly reachable. They also published mitigation guidance. They emphasized that exploitation requires external exposure to the vulnerable endpoint.

How Many Systems Are at Risk

Shadowserver Foundation is monitoring over 470 GoAnywhere MFT instances. It remains unclear how many of these are patched or have their Admin Console secured. Since many organizations share sensitive files through managed file transfer systems, an exposed GoAnywhere instance could provide attackers with access to data or internal systems.

Implications for Security

File transfer tools like GoAnywhere MFT serve a critical role in many enterprises. Attackers often target such systems because they hold valuable data and provide access to internal networks. A remote code execution vulnerability in this context can lead to data breaches, regulatory penalties, or lateral movement in corporate environments.

What Administrators Should Do

Admins should take immediate steps:

  • Upgrade to versions 7.8.4 or 7.6.3 to ensure the patch for CVE-2025-10035 is applied.
  • If upgrade is not yet possible, block external access to the Admin Console.
  • Review configuration to limit exposure and enforce strict network access controls.
  • Monitor internet-facing GoAnywhere MFT endpoints for signs of compromise.

Conclusion

The Fortra max-severity flaw in GoAnywhere MFT’s License Servlet marks a dangerous vulnerability. Because attackers can exploit it remotely, organizations must act fast. Updating the software, restricting public access, and auditing instances are essential. Waiting too long could expose networks, data, and reputation to serious harm.


0 responses to “Fortra max-severity flaw in GoAnywhere MFT License Servlet”