A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.
Is CVE-2025-10035 exploited?
Listed in the CISA KEV catalog on 2025-09-29.
Federal remediation due 2025-10-20.
Past that date by 299 days.
Used in ransomware campaigns.
EPSS puts exploitation in the next 30 days at 99.6%.
Public exploit code: none found in monitored sources.