Beveiligingsadvies

CVE-2025-10035

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-09-18 22:01:51
Laatst bijgewerkt 2026-08-04 03:55:56
Toegewezen door Fortra
CVSS-score 10.0
Status PUBLISHED

Beschrijving

A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.