← Browse CVEs
CVE-2025-10035
Critical · CVSS 10EPSS 99.6%CISA KEVCWE-77
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.
References
Published
Community ground truth
Community verdict
3 verdictsNot a real issue
Includes TruePositive's curated baseline from public sources — community verdicts accrue on top.
to add your verdict.
Community real-world severity: Critical (Critical 3) — CVSS base score 10
In line with its CVSS base score.
Field notes & remediation
Verdicts are the quick signal — notes are the evidence and fixes behind them.
- 0
Confirmed exploited in the wild — listed in the CISA KEV catalog (added 2025-09-29). Linked to known ransomware campaigns. Treat as real and prioritize patching over triage.