Loading HuntDB...

Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability

Added Sept. 29, 2025 Due Oct. 20, 2025 CVE-2025-10035
On Track Fortra / GoAnywhere MFT CWE-502 CWE-77

Description

Fortra GoAnywhere MFT contains a deserialization of untrusted data vulnerability allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.

Required Action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

References

Additional Information

Catalog Version
2025.09.29
Catalog Released
Sept. 29, 2025
Days Until Due
12 days
Last Updated
1 week, 1 day ago