S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Sep 24, 2025

CVE-2025-10035 Scanner

CVE-2025-10035 Scanner - Insecure Deserialization vulnerability in GoAnywhere

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.1k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2025-10035
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
GoAnywhere MFTby Fortra
0
Updated Aug 19, 2026View on NVD →
Detail

The scanner checks the GoAnywhere MFT software for vulnerabilities. GoAnywhere is used by organizations for secure file transfers, ensuring data is exchanged securely between systems and partners. Administrators and IT departments primarily utilize it to automate and manage file transfers in a secure environment. Its adaptability makes it an essential tool in various industries, supporting multiple protocols for seamless interoperability. Maintaining the security and efficiency of file transfers is crucial for businesses that rely on the uninterrupted flow of information. Users depend on GoAnywhere to prevent unauthorized access and data leaks during these transfers.

The vulnerability detected is an insecure deserialization issue within GoAnywhere's License Servlet. This flaw arises when attacker-controlled objects are deserialized, potentially leading to command injection. An attacker can exploit this by providing a valid forged license response signature, which the system deserializes without proper validation. As a result, it presents a critical security risk by potentially allowing remote code execution. Once exploited, this vulnerability could lead to unauthorized access and control over the system.

Technical details involve the vulnerable endpoints being susceptible to deserializing untrusted inputs with attacker-crafted signatures. The exploitation process requires attackers to identify and interact with specific endpoints, such as `/goanywhere/license/Unlicensed.xhtml` or `/license/Unlicensed.xhtml`, using specially crafted requests. These requests may manipulate parameters like `javax.faces.ViewState` and `GARequestAction` to trigger the deserialization flaw. Successful exploitation is apparent when the server redirection includes specific indicators, suggesting vulnerable behavior.

Exploiting this vulnerability could result in severe consequences. Attackers could execute arbitrary commands on the affected system, leading to a complete system compromise. This can jeopardize data integrity and allow unauthorized access to sensitive information. Furthermore, it could disrupt operations, resulting in downtime and significant operational impact. As a result, it emphasizes the importance of addressing this vulnerability promptly to avoid exploitation.

REFERENCES

Solution Advice
  • Immediately update GoAnywhere to the latest version that includes the deserialization fix and other security patches.
  • Implement strong input validation to prevent attacker-controlled data from affecting application logic.
  • Regularly audit and test software for new vulnerabilities and apply patches or workarounds as needed.
  • Enhance authentication mechanisms to prevent unauthorized users from exploiting known endpoints.
  • Conduct regular security training for staff to increase awareness of potential security risks and mitigations.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.