CVE-2025-10035
GoAnywhere MFT License Servlet deserialization -> command injection, unauthenticated with a forged license-response signature (CVSS 10.0)
- Severity
- critical
- Affected product
- GoAnywhere MFT
- Affected versions
- GoAnywhere MFT ≥ 7.7.0, < 7.8.4
- Affected versions
- GoAnywhere MFT < 7.6.3
- Fixed in
- GoAnywhere MFT 7.8.4
- Fixed in
- GoAnywhere MFT 7.6.3
- Added to NewScan
- 2026-08-06
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the GoAnywhere MFT appliance and reports this CVE when the detected version falls inside the affected range below.
Exploited in the wild from Sep 2025 (Fortra/Microsoft; Medusa). Affected up to and including 7.8.3. Split into two rows so a patched 7.6.3 sustain release is not flagged by the 7.8.4 bound if a version source is ever wired up - the fingerprint row has no `version` regex today, so both stay advisory.
APPLIANCE FINGERPRINT
NewScan fingerprints the GoAnywhere MFT appliance and reports this CVE when the detected version falls inside the affected range below.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →