Experts warn of a maximum gravity that goes to the MFT fault is now being exploited as a day zero




  • CVE-2025-10035 in Goanywhere MFT allows critical command injection through the license servlet
  • The exploitation began before public dissemination; Watchtowr found credible evidence in the flow
  • Users urged to patch or isolate systems; Past defects led to the main ransomware CL0P violations

GOANYWHERE MFT, a popular solution of managed files transfer, has a maximum severity vulnerability that is currently exploited in nature after safety researchers Watchtowr Labs claim to have found “credible evidence.”

Fortra (the company behind Goanywhere) recently published a new security notice, urging customers to patch CVE-2025-10035.

Leave a Comment

Your email address will not be published. Required fields are marked *