Ethical Hacking News
A critical security vulnerability in Fortra GoAnywhere Managed File Transfer (MFT) software has been exploited as a 0-day attack just one week before its public disclosure, according to cybersecurity company watchTowr Labs. This exploit highlights the urgent need for organizations to apply patches and take preventative measures to protect themselves against this newly discovered deserialization vulnerability.
A critical security flaw in Fortra GoAnywhere Managed File Transfer (MFT) software has been exploited by attackers just one week before its public disclosure.The vulnerability, CVE-2025-10035, affects Fortra GoAnywhere version 7.8.4 or Sustain Release 7.6.3 and allows for authentication bypass and command injection.The exploit has already been detected in the wild since at least September 10, 2025, highlighting the need for prompt patching.Organizations are urged to apply critical patches released by Fortra to protect against this newly discovered deserialization vulnerability.
The world of cybersecurity is constantly evolving, with new threats and vulnerabilities emerging on a daily basis. Recently, a critical security flaw in Fortra GoAnywhere Managed File Transfer (MFT) software has been exploited by attackers just one week before its public disclosure. This recent development highlights the need for organizations to stay vigilant and take proactive measures to protect themselves against this newly discovered deserialization vulnerability.
According to watchTowr Labs, a cybersecurity company that has provided insight into the exploit, the vulnerability in question is CVE-2025-10035, which affects Fortra GoAnywhere version 7.8.4 or Sustain Release 7.6.3. This vulnerability allows an attacker to send a crafted HTTP GET request to the "/goanywhere/license/Unlicensed.xhtml/" endpoint, directly interacting with the License Servlet ("com.linoma.ga.ui.admin.servlet.LicenseResponseServlet") that is exposed at "/goanywhere/lic/accept/" using the GUID embedded in the response to the earlier sent request. This authentication bypass enables an attacker to take advantage of inadequate deserialization protections in the License Servlet, resulting in command injection.
Benjamin Harris, CEO and Founder of watchTowr, emphasized that this is not a "just" CVSS 10.0 flaw in a solution long favored by APT groups and ransomware operators – it is a vulnerability that has been actively exploited in the wild since at least September 10, 2025. He further noted that this exploit demonstrates the importance of applying patches quickly to prevent potential attacks.
The cybersecurity company also provided evidence of exploitation efforts, including a stack trace, which enables the creation of a backdoor account. The sequence of the activity is as follows:
* Triggering the pre-authentication vulnerability in Fortra GoAnywhere MFT to achieve remote code execution (RCE)
* Using the RCE to create a GoAnywhere user named "admin-go"
* Using the newly created account to create a web user
* Leveraging the web user to interact with the solution and upload and execute additional payloads, including SimpleHelp and an unknown implant ("zato_be.exe")
The threat actor activity originated from the IP address 155.2.190[.]197, which has been flagged for conducting brute-force attacks targeting Fortinet FortiGate SSL VPN appliances in early August 2025.
Given signs of in-the-wild exploitation, it is imperative that users move quickly to apply the fixes, if not already. The importance of prompt action cannot be overstated, as this vulnerability has the potential to cause significant damage to organizations and their sensitive data.
In response to this critical security flaw, Fortra released a critical patch for CVE-2025-10035 earlier today. Organizations are urged to take immediate action to apply these patches and ensure that their systems are protected against this newly discovered deserialization vulnerability.
The recent exploitation of the Fortra GoAnywhere CVSS 10 flaw serves as a stark reminder of the importance of ongoing cybersecurity vigilance and proactive measures to protect sensitive data. As new threats emerge, it is crucial for organizations to stay informed and take swift action to mitigate potential risks.
In conclusion, the recent exploit of the Fortra GoAnywhere CVSS 10 flaw highlights the urgent need for organizations to prioritize their cybersecurity posture and take prompt action to address this newly discovered deserialization vulnerability. By staying vigilant and proactive, organizations can minimize the risk of potential attacks and protect their sensitive data from harm.
Related Information:
https://www.ethicalhackingnews.com/articles/Fortra-GoAnywhere-CVSS-10-Flaw-Exploited-as-0-Day-a-Week-Before-Public-Disclosure-A-Call-to-Action-for-Organizations-ehn.shtml
https://thehackernews.com/2025/09/fortra-goanywhere-cvss-10-flaw.html
https://thehackernews.com/2025/09/fortra-releases-critical-patch-for-cvss.html
https://nvd.nist.gov/vuln/detail/CVE-2025-10035
https://www.cvedetails.com/cve/CVE-2025-10035/
Published: Fri Sep 26 08:13:31 2025 by llama3.2 3B Q4_K_M