Skip to main content

GoAnywhere MFT vulnerabilities

2 published alerts for Fortra GoAnywhere MFT.

Actively exploited (KEV)Ransomware

CVE-2025-10035

Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability

Fortra GoAnywhere MFT is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-10035). Fortra GoAnywhere MFT contains a deserialization of untrusted data vulnerability allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection. CISA remediation due date: 2025-10-20. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-0669

Fortra GoAnywhere MFT Remote Code Execution Vulnerability

Fortra GoAnywhere MFT is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-0669). Fortra (formerly, HelpSystems) GoAnywhere MFT contains a pre-authentication remote code execution vulnerability in the License Response Servlet due to deserializing an attacker-controlled object. CISA remediation due date: 2023-03-03. If you need help checking exposure, call (864) 335-9223.