Experts warn a maximum severity GoAnywhere MFT flaw is now being exploited as a zero day




  • CVE-2025-10035 in GoAnywhere MFT allows critical command injection via license servlet
  • Exploitation began before public disclosure; WatchTowr found credible in-the-wild evidence
  • Users urged to patch or isolate systems; past flaws led to major Cl0p ransomware breaches

GoAnywhere MFT, a popular managed file transfer solution, is carrying a maximum-severity vulnerability currently being exploited in the wild after security researchers WatchTowr Labs claim to have found “credible evidence”.

Fortra (the company behind GoAnywhere) recently published a new security advisory, urging customers to patch CVE-2025-10035.

https://cdn.mos.cms.futurecdn.net/GJ8T4oA8G7TYJwTEhkwJAF-2560-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img