CVE-2025-10035
A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 99.80%
- CISA KEV
- Known exploited vulnerability
- CWE
- CWE-77, CWE-502
- Published
- 2025-09-18
- Last modified
- 2026-08-04
Affected products
- Fortra GoAnywhere MFT
Weakness type
Related vulnerabilities
- CVE-2026-81048 — Dell ThinOS 10, versions prior to 2605_10.2616, contain an Improper Neutralization of Special...
- CVE-2026-78484 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-79945 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-78493 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-79741 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-79941 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-83948 — Microsoft Azure CLI Remote Code Execution Vulnerability
- CVE-2026-81380 — GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability