Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Fortra GoAnywhere MFT Deserialization Vulnerability in License Servlet Allowing Command Injection

Vulnerability

A deserialization vulnerability has been identified in the License Servlet of Fortra's GoAnywhere MFT. This vulnerability allows an actor with a validly forged license response signature to deserialize an arbitrary, actor-controlled object, which could potentially lead to command injection.

Impact

Exploitation of this vulnerability could result in arbitrary command execution on the server where GoAnywhere MFT is running.

Remediation

Users are advised to upgrade to the latest patched version (7.8.4) or the Sustain Release 7.6.3. Additionally, access to the GoAnywhere Admin Console should not be open to the public, as exploitation is highly dependent on the system being externally exposed to the internet.

Added: Sep 18, 2025, 10:22 PM
Updated: Sep 29, 2025, 5:13 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
10.0
exploitability
9.3
remediation
7.9
relevance
0.5
threat
9.2
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.