CVE-2025-10035Critical· 10.0▾ Hadal⚠ Exploited in the wildA deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.
▾ Hadal zone — Critical and actively exploited (CISA KEV / 0day)
impact 55 · likelihood 19.9 · exploitation 25 · ransomware 5
The latest CVEs are free to read. CVE-2025-10035 is outside the free window — sign in (free) to view the full technical detail, affected versions, references, and raw markdown.