← All CVEs NewScan detects
critical

CVE-2025-10035

GoAnywhere MFT License Servlet deserialization -> command injection, unauthenticated with a forged license-response signature (CVSS 10.0)

Severity
critical
Affected product
GoAnywhere MFT
Affected versions
GoAnywhere MFT ≥ 7.7.0, < 7.8.4
Affected versions
GoAnywhere MFT < 7.6.3
Fixed in
GoAnywhere MFT 7.8.4
Fixed in
GoAnywhere MFT 7.6.3
Added to NewScan
2026-08-06
Detected by
NewScan — free, self-hosted

How NewScan reports it

APPLIANCE FINGERPRINT

NewScan fingerprints the GoAnywhere MFT appliance and reports this CVE when the detected version falls inside the affected range below.

Exploited in the wild from Sep 2025 (Fortra/Microsoft; Medusa). Affected up to and including 7.8.3. Split into two rows so a patched 7.6.3 sustain release is not flagged by the 7.8.4 bound if a version source is ever wired up - the fingerprint row has no `version` regex today, so both stay advisory.

APPLIANCE FINGERPRINT

NewScan fingerprints the GoAnywhere MFT appliance and reports this CVE when the detected version falls inside the affected range below.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →