Fortra GoAnywhere MFT Zero-Day Exploited in Ransomware Attacks
A recently patched vulnerability in Fortra GoAnywhere MFT (Managed File Transfer) was exploited as a zero-day by a Chinese ransomware group, Microsoft reports. The flaw, tracked as CVE-2025-10035 (CVSS score of 10/10), was disclosed on September 18, when Fortra rolled out patches for it. A deserialization issue in the application’s license servlet, the bug can be exploited for command injection and remote code execution (RCE). Shortly after public disclosure, cybersecurity firm watchTowr warned that the…
Read More
