Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Fortra Patches Critical GoAnywhere MFT Vulnerability

Fortra Patches Critical GoAnywhere MFT Vulnerability

Posted on September 22, 2025September 22, 2025 By CWS

Fortra has launched patches for a critical-severity vulnerability within the GoAnywhere safe managed file switch (MFT) software program that might be exploited for command injection.

GoAnywhere MFT is an enterprise software that permits organizations to automate and safe the trade of information with their buying and selling companions.

Tracked as CVE-2025-10035 (CVSS rating of 10), the vital bug is described as a deserialization of untrusted knowledge difficulty affecting the appliance’s license servlet.

In line with Fortra’s advisory, the bug might be exploited by “an actor with a validly cast license response signature to deserialize an arbitrary actor-controlled object, presumably resulting in command injection”.

Profitable exploitation of the flaw, Rapid7 warns, may permit unauthenticated attackers to attain distant code execution (RCE) on weak GoAnywhere MFT cases.

Fortra included patches for the safety defect in GoAnywhere MFT model 7.8.4 and GoAnywhere MFT Maintain model 7.6.3 and urged prospects to make sure that the GoAnywhere Admin Console is just not accessible to the general public.

“Exploitation of this vulnerability is very dependent upon techniques being externally uncovered to the web,” the corporate notes.

Fortra additionally advises prospects to observe Admin Audit logs for suspicious exercise and to look in log recordsdata for errors containing the SignedObject.getObject: string in exception stack traces, which signifies affect from the vulnerability.Commercial. Scroll to proceed studying.

Nevertheless, Fortra makes no point out of this vulnerability being exploited within the wild and Rapid7 notes that it has not seen public exploit code both.

“Nevertheless, given the character and historical past of this product, this new vulnerability needs to be handled as a major risk,” Rapid7 notes.

In 2023, hackers related to the notorious Cl0p ransomware operation exploited a zero-day vulnerability (CVE-2023-0669) in Fortra’s file switch product, created unauthorized accounts on buyer environments and stole knowledge from dozens of organizations.

Associated: CISA Analyzes Malware From Ivanti EPMM Intrusions

Associated: Unpatched Vulnerabilities Expose Novakon HMIs to Distant Hacking

Associated: Crucial Infrastructure Operators Implementing Zero Belief in OT Environments

Associated: OpenSMTPD Vulnerability Results in Command Injection

Security Week News Tags:Critical, Fortra, GoAnywhere, MFT, Patches, Vulnerability

Post navigation

Previous Post: Massive Cyber-Attack Attacking macOS Users via GitHub Pages to Deliver Stealer Malware
Next Post: New Botnet Leverages DNS Misconfiguration to Launch Massive Cyber Attack

Related Posts

SimpleHelp Vulnerability Exploited Against Utility Billing Software Users SimpleHelp Vulnerability Exploited Against Utility Billing Software Users Security Week News
Vulnerability Allowed Scraping of 3.5 Billion WhatsApp Accounts Vulnerability Allowed Scraping of 3.5 Billion WhatsApp Accounts Security Week News
Armis Raises 5 Million in Pre-IPO Funding Round at .1 Billion Valuation Armis Raises $435 Million in Pre-IPO Funding Round at $6.1 Billion Valuation Security Week News
QNAP NetBak PC Agent Affected by Recent ASP.NET Core Vulnerability QNAP NetBak PC Agent Affected by Recent ASP.NET Core Vulnerability Security Week News
Over 73,000 WatchGuard Firebox Devices Impacted by Recent Critical Flaw Over 73,000 WatchGuard Firebox Devices Impacted by Recent Critical Flaw Security Week News
Data Stolen in Eurofiber France Hack Data Stolen in Eurofiber France Hack Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • NGINX Vulnerability Exploited in Web Traffic Hijacking
  • New Malvertising Threat Exploits Facebook Ads for Scams
  • Critical TP-Link Vulnerabilities Demand Immediate Firmware Updates
  • CISA Alerts on VMware ESXi Vulnerability in Ransomware
  • Cybercriminals Exploit Cloud Services for Phishing

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • NGINX Vulnerability Exploited in Web Traffic Hijacking
  • New Malvertising Threat Exploits Facebook Ads for Scams
  • Critical TP-Link Vulnerabilities Demand Immediate Firmware Updates
  • CISA Alerts on VMware ESXi Vulnerability in Ransomware
  • Cybercriminals Exploit Cloud Services for Phishing

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark