VYPR
Critical severity10.0CISA KEVNVD Advisory· Published Sep 18, 2025· Updated Aug 4, 2026

CVE-2025-10035

CVE-2025-10035

Description

A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3

Patches

Vulnerability mechanics

References

2

News mentions

3