Ethical Hacking News
A critical vulnerability was exposed in Fortra GoAnywhere MFT software, allowing hackers to exploit it before a public alert was issued. The vulnerability, tracked as CVE-2025-10035, is a deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT. Cybersecurity experts urge customers to upgrade to a patched version and restrict public access to the GoAnywhere Admin Console to mitigate the risk.
Fortra GoAnywhere Managed File Transfer (MFT) software has been compromised by hackers due to a deserialization vulnerability. The vulnerability, CVE-2025-10035, allows attackers to execute arbitrary commands on affected systems. WatchTowr Labs first detected the attack in September 2025, eight days before the public advisory was published. Cybersecurity experts found a chain of three separate issues: an access control bypass, unsafe deserialization vulnerability, and unknown issue with private key knowledge. Fortra addressed the critical vulnerability on September 18 and recommended upgrading to a patched version or restricting public access to the GoAnywhere Admin Console.
Fortra GoAnywhere Managed File Transfer (MFT) software, a comprehensive solution for secure file transfer, data encryption, and compliance management, has been compromised by hackers. The vulnerability, tracked as CVE-2025-10035, is a deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT. This flaw allows an attacker to execute arbitrary commands on affected systems.
The attack was first detected by watchTowr Labs, a cybersecurity firm that discovered 'credible evidence' of exploitation dating back to September 10, 2025, eight days before the public advisory was published. The company's analysis revealed that the vulnerability was actively exploited in attacks in the wild as early as September 10, 2025.
Cybersecurity experts at Rapid7 also analyzed the vulnerability and found that it is not a simple deserialization issue but rather a chain of three separate issues: an access control bypass known since 2023, an unsafe deserialization vulnerability CVE-2025-10035, and an as-yet unknown issue pertaining to how attackers can know a specific private key.
Fortra addressed the critical vulnerability on September 18, urging customers to upgrade to a patched version (the latest release 7.8.4 or the Sustain Release 7.6.3). To mitigate the vulnerability, Fortra recommends restricting public access to the GoAnywhere Admin Console, as exploitation depends on internet exposure.
The discovery of this critical flaw highlights the importance of timely patching and proper security measures in place. Cybersecurity experts stress that defenders should immediately change how they think about timelines and risk, given the fact that watchTowr found over 20,000 internet-facing GoAnywhere MFT instances, including Fortune 500 companies.
Furthermore, Microsoft recently discovered a new variant of XCSSET macOS malware in targeted attacks, while the UK NCSC warned that attackers exploited Cisco firewall zero-days to deploy RayInitiator and LINE VIPER malware. These recent incidents demonstrate the ongoing threat landscape and the need for organizations to stay vigilant and proactive in protecting their systems against emerging threats.
Related Information:
https://www.ethicalhackingnews.com/articles/Hackers-Exploit-Fortra-GoAnywhere-Flaw-Before-Public-Alert-A-Critical-Vulnerability-Exposed-ehn.shtml
https://securityaffairs.com/182647/hacking/hackers-exploit-fortra-goanywhere-flaw-before-public-alert.html
https://nvd.nist.gov/vuln/detail/CVE-2025-10035
https://www.cvedetails.com/cve/CVE-2025-10035/
Published: Sat Sep 27 01:01:46 2025 by llama3.2 3B Q4_K_M