Fortra GoAnywhere MFT contains an insecure deserialization vulnerability in the License Servlet caused by deserializing attacker-controlled objects with a valid forged license response signature, letting attackers perform command injection, exploit requires valid forged license signature.
id: CVE-2025-10035
info:
name: GoAnywhere - Authentication Bypass
author: DhiyaneshDk,watchtowr
...