{"api_version":"1","generated_at":"2026-08-16T16:32:48+00:00","cve":"CVE-2025-10035","urls":{"html":"https://cve.report/CVE-2025-10035","api":"https://cve.report/api/cve/CVE-2025-10035.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2025-10035","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2025-10035"},"summary":{"title":"Deserialization Vulnerability in GoAnywhere MFT's License Servlet","description":"A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.","state":"PUBLISHED","assigner":"Fortra","published_at":"2025-09-18 22:15:41","updated_at":"2026-08-04 05:16:33"},"problem_types":["CWE-77","CWE-502","CWE-77 CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')","CWE-502 CWE-502 Deserialization of Untrusted Data"],"metrics":[{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"df4dee71-de3a-4139-9588-11b62fe6c0ff","type":"Secondary","score":"10","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","baseScore":10,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"10","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":10,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://www.fortra.com/security/advisories/product-security/fi-2025-012","name":"https://www.fortra.com/security/advisories/product-security/fi-2025-012","refsource":"df4dee71-de3a-4139-9588-11b62fe6c0ff","tags":["Vendor Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-10035","name":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-10035","refsource":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-10035","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-10035","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Fortra","product":"GoAnywhere MFT","version":"affected 7.8.3 semver","platforms":["Linux","Windows","MacOS"]}],"timeline":[{"source":"ADP","time":"2025-09-29T00:00:00.000Z","lang":"en","value":"CVE-2025-10035 added to CISA KEV"}],"solutions":[{"source":"CNA","title":"","value":"Upgrade to a patched version (the latest release 7.8.4, or the Sustain Release 7.6.3)","time":"","lang":"en"}],"workarounds":[{"source":"CNA","title":"","value":"Immediately ensure that access to the GoAnywhere Admin Console is not open to the public. Exploitation of this vulnerability is highly dependent upon systems being externally exposed to the internet.","time":"","lang":"en"}],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2025","cve_id":"10035","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"fortra","cpe5":"goanywhere_managed_file_transfer","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":{"cve_year":"2025","cve_id":"10035","cve":"CVE-2025-10035","vendorProject":"Fortra","product":"GoAnywhere MFT","vulnerabilityName":"Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability","dateAdded":"2025-09-29","shortDescription":"Fortra GoAnywhere MFT contains a deserialization of untrusted data vulnerability allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","dueDate":"2025-10-20","knownRansomwareCampaignUse":"Known","notes":"https://www.fortra.com/security/advisories/product-security/fi-2025-012 ; https://nvd.nist.gov/vuln/detail/CVE-2025-10035","cwes":"CWE-502,CWE-77","catalogVersion":"2026.08.14","updated_at":"2026-08-14 17:14:38"},"epss":{"cve_year":"2025","cve_id":"10035","cve":"CVE-2025-10035","epss":"0.996140000","percentile":"0.999470000","score_date":"2026-08-15","updated_at":"2026-08-16 00:00:41"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2025-10035","options":[{"Exploitation":"active"},{"Automatable":"yes"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2025-09-19T00:00:00+00:00","version":"2.0.3"},"type":"ssvc"}},{"other":{"content":{"dateAdded":"2025-09-29","reference":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-10035"},"type":"kev"}}],"providerMetadata":{"dateUpdated":"2026-08-04T03:55:56.207Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"references":[{"tags":["government-resource"],"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-10035"}],"timeline":[{"lang":"en","time":"2025-09-29T00:00:00.000Z","value":"CVE-2025-10035 added to CISA KEV"}],"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"affected","platforms":["Linux","Windows","MacOS"],"product":"GoAnywhere MFT","vendor":"Fortra","versions":[{"lessThanOrEqual":"7.8.3","status":"affected","version":"0","versionType":"semver"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to <span style=\"background-color: rgb(255, 255, 255);\">deserialize an arbitrary actor-controlled object, possibly leading to command injection.</span>"}],"value":"A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection."}],"impacts":[{"capecId":"CAPEC-248","descriptions":[{"lang":"en","value":"CAPEC-248 Command Injection"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":10,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-77","description":"CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')","lang":"en","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-502","description":"CWE-502 Deserialization of Untrusted Data","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2025-09-18T22:43:41.684Z","orgId":"df4dee71-de3a-4139-9588-11b62fe6c0ff","shortName":"Fortra"},"references":[{"url":"https://www.fortra.com/security/advisories/product-security/fi-2025-012"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Upgrade to a patched version (the latest release 7.8.4, or the Sustain Release 7.6.3)"}],"value":"Upgrade to a patched version (the latest release 7.8.4, or the Sustain Release 7.6.3)"}],"source":{"discovery":"UNKNOWN"},"title":"Deserialization Vulnerability in GoAnywhere MFT's License Servlet","workarounds":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<span style=\"background-color: rgb(255, 255, 255);\">\n\nImmediately ensure that access to the GoAnywhere Admin Console is not open to the public. Exploitation of this vulnerability is highly dependent upon systems being externally exposed to the internet. \n\n</span>\n\n<br>"}],"value":"Immediately ensure that access to the GoAnywhere Admin Console is not open to the public. Exploitation of this vulnerability is highly dependent upon systems being externally exposed to the internet."}],"x_generator":{"engine":"Vulnogram 0.2.0"}}},"cveMetadata":{"assignerOrgId":"df4dee71-de3a-4139-9588-11b62fe6c0ff","assignerShortName":"Fortra","cveId":"CVE-2025-10035","datePublished":"2025-09-18T22:01:51.337Z","dateReserved":"2025-09-05T16:43:32.877Z","dateUpdated":"2026-08-04T03:55:56.207Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2025-09-18 22:15:41","lastModifiedDate":"2026-08-04 05:16:33","problem_types":["CWE-77","CWE-502","CWE-77 CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')","CWE-502 CWE-502 Deserialization of Untrusted Data"],"metrics":{"cvssMetricV31":[{"source":"df4dee71-de3a-4139-9588-11b62fe6c0ff","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","baseScore":10,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-09-19T00:00:00+00:00","id":"CVE-2025-10035","options":[{"exploitation":"active"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:fortra:goanywhere_managed_file_transfer:*:*:*:*:*:*:*:*","versionEndExcluding":"7.6.3","matchCriteriaId":"CF143971-7546-4C90-B0D0-A3E08536BF4F"},{"vulnerable":true,"criteria":"cpe:2.3:a:fortra:goanywhere_managed_file_transfer:*:*:*:*:*:*:*:*","versionStartIncluding":"7.7.0","versionEndExcluding":"7.8.4","matchCriteriaId":"479CA63D-4C41-4CA1-9655-A8BD43311CEA"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2025","CveId":"10035","Ordinal":"1","Title":"Deserialization Vulnerability in GoAnywhere MFT's License Servle","CVE":"CVE-2025-10035","Year":"2025"},"notes":[{"CveYear":"2025","CveId":"10035","Ordinal":"1","NoteData":"A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.","Type":"Description","Title":"Deserialization Vulnerability in GoAnywhere MFT's License Servle"}]}}}