Recent Fortra GoAnywhere MFT Vulnerability Exploited as Zero-Day
A critical deserialization vulnerability in Fortra GoAnywhere MFT (CVE-2025-10035) was exploited in the wild at least eight days before patches were released.
A deserialization vulnerability in GoAnywhere MFT (CVE-2025-10035) can enable remote code execution; apply provided patches and restrict Admin Console exposure.