Known vulnerability record

CVE-2025-10035

Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability

Stable IDcve:CVE-2025-10035Last updatedLast verifiedLegacy review pendingProvenanceCISA KEV + CVE record + EPSS

Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability

Fortra GoAnywhere MFT contains a deserialization of untrusted data vulnerability allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.

Keep the signals separate

CVSS severitycriticalScore 10 · source Fortra
EPSS probability99.6%Probability of exploitation in the next 30 days; not severity
CISA KEVKnown exploitedAdded 2025-09-29
Ransomware useknownPreserved as known / unknown, not a truthy default

Dates and provenance

CVE published
2025-09-18
CVE modified
2026-08-04
KEV date added
2025-09-29
Dataset fetched
2026-08-21T03:55:01.236Z

Original records

Version history: normalized permanent page created 2026-08-20. Machine-enriched fields remain source-attributed.