CVE-2025-10035Active Exploitation(fortra / goanywhere_managed_file_transfer)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch fortra goanywhere_managed_file_transfer systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.

5.8/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-10-20. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-77CWE-502

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • goanywhere_managed_file_transfer

Threat summary

  • Active exploitation appears in 10 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 15 mentions across 10 observed days

What's happening

  • Active exploitation reported across 10 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 5 signals
  • General: 3 classified signals
  • Disclosure: 1 classified signal
  • Peaked 6d ago at 4 mentions (2026-04-06); latest day: 1
  • 15 total mentions across 10 days

Affected systems

Vendors
Products
goanywhere_managed_file_transfer

Deep dive

Activity timeline15 mentions / 10d
01234Mentions · 2026-02-05: 1Mentions · 2026-02-10: 1Mentions · 2026-02-11: 1Mentions · 2026-04-06: 4Mentions · 2026-04-07: 2Mentions · 2026-04-08: 1Mentions · 2026-07-17: 1Mentions · 2026-07-21: 2Mentions · 2026-07-29: 1Mentions · 2026-08-19: 1PoC Mentioned / Linked · 2026-02-10: 1PoC Mentioned / Linked · 2026-02-11: 1Active Exploitation · 2026-02-11: 1Active Exploitation · 2026-04-06: 3Active Exploitation · 2026-04-07: 1Active Exploitation · 2026-04-08: 1Active Exploitation · 2026-07-17: 1Active Exploitation · 2026-07-21: 1Active Exploitation · 2026-07-29: 1Active Exploitation · 2026-08-19: 1Patch / Workaround · 2026-04-06: 2Patch / Workaround · 2026-04-07: 2Patch / Workaround · 2026-07-21: 1Technical Details · 2026-02-10: 1Technical Details · 2026-04-06: 2Technical Details · 2026-07-17: 1Technical Details · 2026-07-21: 102-0502-1002-1104-0604-0704-0807-1707-2107-2908-19
Signal classification4 categories
Active Exploitation
1066.7%
General
320.0%
Disclosure
16.7%
Patch
16.7%
Referenced assets23 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-051
General1
2026-02-101
Disclosure1
2026-02-111
Active Exploitation1
2026-04-064
Active Exploitation3General1
2026-04-072
Active Exploitation1Patch1
2026-04-081
Active Exploitation1
2026-07-171
Active Exploitation1
2026-07-212
Active Exploitation1General1
2026-07-291
Active Exploitation1
2026-08-191
Active Exploitation1
Full discourse15 posts
  • reverseame@reverseame
    Active Exploitation

    It Is Bad (Exploitation of Fortra GoAnywhere MFT CVE-2025-10035) - Part 2 #CVE202510035 #GoAnywhereMFT #InTheWildExploitation #SecurityTransparency #BackdoorAccount https://labs.watchtowr.com/it-is-bad-exploitation-of-fortra-goanywhere-mft-cve-2025-10035-part-2/

    Post summary

    The tweet signals that CVE‑2025‑10035 in Fortra GoAnywhere MFT is being exploited in the wild, and it links to an article that likely contains PoC details.

    06022131.7K
    21.6K followersView on X
  • reverseame@reverseame
    Disclosure

    Is This Bad? This Feels Bad. (Fortra GoAnywhere CVE-2025-10035) #GoAnywhereMFT #CVE202510035 #Deserialization #AuthBypass #PreAuthRCE https://labs.watchtowr.com/is-this-bad-this-feels-bad-goanywhere-cve-2025-10035/

    Post summary

    The tweet announces a pre-auth remote code execution vulnerability in Fortra GoAnywhere (CVE‑2025‑10035), highlighting deserialization and authentication bypass, and links to a detailed article.

    0201161.4K
    21.6K followersView on X
  • CVE Brief@DailyCVEBrief
    Active Exploitation

    LOOK BACK: Fortra patched a GoAnywhere deserialization bug in 2023 by wrapping it in three checks. One of them whitelisted SignedObject, whose getObject() deserializes again. CVE-2025-10035 was that same sink, reopened, and Medusa ransomware got there first. https://t.co/XmFDwd1O2j

    Post summary

    The GoAnywhere deserialization flaw CVE‑2025‑10035, re‑opened by an earlier patch oversight, was exploited by Medusa ransomware in the wild; the vulnerability details and patch information are present.

    1000040
    21 followersView on X
  • @pedri77@pedri77
    Active Exploitation

    Storm-1175 exploits GoAnywhere MFT flaw CVE-2025-10035 in Medusa attacks, allowing easy remote code execution via License Servlet bug. A cybercrime group, tracked as Storm-1175, has been actively exploiting a maximum se... https://f.mtr.cool/yybuznoyhy

    Post summary

    Storm‑1175 is actively exploiting CVE‑2025‑10035 in GoAnywhere MFT, leveraging a License Servlet bug to achieve remote code execution. No mitigation or PoC details are disclosed.

    0001081
    2.1K followersView on X
  • Martin Brindley@martinbrindley
    General

    Hidden Cost of MFT Vulnerabilities: Why CVE-2025-10035 Demands a New Security Playbook https://www.itsecurityguru.org/2025/10/13/hidden-cost-of-mft-vulnerabilities-why-cve-2025-10035-demands-a-new-security-playbook/ @Kiteworks

    Post summary

    The passage only references a CVE number in a headline, providing no technical, exploit, or mitigation details.

    0001036
    1.1K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows Medusa ransomware actors are rapidly exploiting CVE-2025-10035 and CVE-2026-23760 for initial access, then using RDP and remote management tools for lateral movement. Runtime segmentation helps limit blast radius once attackers pivot internally. #Ransomware 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/medusa-ransomware-cisa-advisory-2026

    Post summary

    The post confirms that Medusa ransomware actors are actively exploiting CVE-2025-10035 and CVE-2026-23760 for initial access, then leveraging RDP and management tools for lateral movement.

    0000060
    1.9K followersView on X
  • @pedri77@pedri77
    Active Exploitation

    Fortra on Thursday revealed the results of its investigation into CVE-2025-10035, a critical security flaw in GoAnywhere Managed File Transfer (MFT) that's assessed to have come under active exploitation since at le... https://f.mtr.cool/ykicdycxgg

    Post summary

    Fortra reports that CVE-2025-10035 in GoAnywhere Managed File Transfer is being actively exploited, but does not provide specific exploit details or remediation steps.

    0000057
    2.1K followersView on X
  • CVE Brief@DailyCVEBrief
    General

    Full Look Back: how the 2023 fix created the 2025 bug, and the question three security firms couldn't answer, namely how attackers got the private signing key. https://cvebrief.com/cve/CVE-2025-10035/ https://t.co/ufbzjQRZJB

    Post summary

    The tweet only references a CVE with a brief description and a link, but does not provide PoC, exploitation details, patch info, or technical specifics.

    000004
    21 followersView on X
  • 상식과 정의@cheolsoo8
    Active Exploitation

    https://naver.me/5su9GoRg 마이크로소프트(MS) 위협 인텔리전스 팀의 최신 조사 결과에 따르면, 이들은 보안 패치가 배포되기 전인 취약점 ‘CVE-2025-10035’ 등을 악용해 시스템을 장악한 것으로 확인됐다. 지난 2023년을 기점으로 MS 익스체인지(Exchange) 서버 등을 포함해 16개 이상의 심각한 보안

    Post summary

    The article confirms that CVE-2025-10035 was actively exploited against Microsoft Exchange before a patch became available.

    00000430
    3.1K followersView on X
  • Swapnil Mengi@swapnil_mengi
    Patch

    THREAT ALERT: Storm-1175 Blitz China-linked group weaponizing zero-days in SmarterMail (CVE-2026-23760) & GoAnywhere (CVE-2025-10035) for Medusa Ransomware. ⏱️ Speed: <24hrs to encrypt 🎯 Target: Edge assets (VPN/Mail) 🛡️ Action: Patch NOW #CyberSecurity #ZeroDay #Storm1175

    Post summary

    The alert warns that Storm-1175 is weaponizing zero‑day vulnerabilities (CVE‑2026‑23760 and CVE‑2025‑10035) targeting SmarterMail and GoAnywhere, urging immediate patching to prevent potential Medusa ransomware attacks.

    00000175
    42 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    Storm-1175 exploited zero-day vulnerabilities CVE-2025-10035 and CVE-2026-23760 to deploy Medusa ransomware within 24 hours of initial compromise. The China-based group rapidly escalated privileges, moved laterally through credential theft, and exfiltrated data before encryption. Runtime segmentation can limit blast radius during such high-tempo operations. #ZeroDay #Ransomware 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/storm-1175-medusa-ransomware-zero-day-attacks-2026

    Post summary

    Storm‑1175 used newly discovered CVEs to quickly deploy Medusa ransomware, demonstrating active exploitation, while recommending runtime segmentation as a mitigation.

    00000232
    1.9K followersView on X
  • Syed Aquib@syedaquib77
    Active Exploitation

    🚨 Threat Alert: Medusa ransomware campaigns (Storm-1175 / Medusa affiliates) 📅 Date: 2026-04-06 📆 Timeline: Medusa RaaS tracked since 2023; Storm-1175 rapidly weaponized N-days and multiple zero-days (e.g., CVE-2026-23760 SmarterMail, CVE-2025-10035 GoAnywhere MFT) across 2025–2026. Microsoft published Storm-1175 analysis 2026-04-06; Symantec/Broadcom reported Lazarus-linked Medusa use in Feb 2026. 📍 Location: United States (MS, NJ and other states); activity also observed impacting organizations in the United Kingdom and Australia 📌 Attribution: Primary: Microsoft tracks actor as Storm-1175 (financially motivated affiliates using Medusa). Additional reporting links some Medusa deployments to Lazarus‑linked actors. Confidence: medium — Medusa is a RaaS used by multiple affiliate sets; single origin not definitive. 📝 Summary: Microsoft and other vendors report high-tempo Medusa ransomware campaigns that weaponize zero-day and recently disclosed (N-day) vulnerabilities to compromise internet‑facing systems, rapidly exfiltrate data, and deploy Medusa. Intrusions can progress from initial access to exfiltration and encryption within 24 hours; typical dwell ~5–6 days. Recent victims include healthcare, municipal, education, professional services, and finance. ⚔️ Attack Details: - Attack Type: Ransomware (Medusa) leveraging zero-day / recently‑disclosed vulnerability exploitation and human‑operated intrusion techniques - Target: Healthcare (e.g., University of Mississippi Medical Center), municipal governments (Passaic County, NJ), education, professional services, finance; internet‑facing services and administrative systems 📈 Impact: Data exfiltration (double‑extortion), system encryption, operational disruption (hospital impact, county phone outages), rapid full compromise in some incidents. Typical 5–6 day campaigns; higher remediation/recovery costs. Example ransom indicator: observed average ~ $260,000 in some cases (Symantec, Feb 2026). 🔗 Related Resources: - https://www.microsoft.com/en-us/security/blog/2026/04/06/storm-1175-focuses-gaze-on-vulnerable-web-facing-assets-in-high-tempo-medusa-ransomware-operations/ - https://therecord.media/medusa-ransomware-group-zero-days-microsoft - https://therecord.media/medusa-ransomware-mississippi-cyber - https://therecord.media/new-jersey-county-says-malware-attack-took-down-phones - https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-071a - https://www.halcyon.ai/threat-group/medusa - https://www.broadcom.com/support/security-center/protection-bulletin/medusa-ransomware-distributed-by-the-lazarus-threat-group - https://thehackernews.com/2026/02/lazarus-group-uses-medusa-ransomware-in.html 🛡️ Recommended Actions: - Prioritize patching of internet‑facing systems; accelerate N-day/zero-day remediation. - Inventory and reduce public attack surface; place web‑facing services behind WAFs/reverse proxies. - Enforce MFA and least privilege for admin and RMM accounts; rotate/reset credentials if compromise suspected. - Restrict, harden, and monitor RMM/remote‑access tools (ConnectWise ScreenConnect, AnyDesk, SimpleHelp); require MFA. - Enable tamper protection and EDR/XDR; apply attack‑surface reduction (block LSASS dumping, block PsExec/WMI process chains). - Monitor for anomalous exfiltration (Rclone, Bandizip) and cloud uploads; log and alert on new admin accounts and firewall rule changes. - Segment networks, disable unused RDP, and isolate critical systems from web tiers. - Maintain offline, immutable backups and test recovery; implement IR playbooks for rapid containment. 🫨 Attack Vectors: - T1190 - Exploit Public-Facing Application (weaponized N-day/zero-day; web shells) - T1136 - Create Account (new local/admin accounts for persistence) - T1021 / T1219 - Remote Services / Remote Access Tools (ConnectWise ScreenConnect, AnyDesk, SimpleHelp) - T1078 - Valid Accounts (compromised/legitimate credentials) - T1003 - OS Credential Dumping (LSASS dumping, Mimikatz) - T1041 - Exfiltration Over C2 Channel (Rclone, Bandizip) - T1486 - Data Encrypted for Impact (Medusa deployment) - T1566/T1059 - Living‑off‑the‑land and scripted execution (PowerShell, PsExec, Impacket) 🏷 Tags: #ransomware #Medusa #Storm-1175 #zero-day #exploitation #healthcare #municipal #remote-access #data-exfiltration #CISA #Microsoft #Lazarus #Cybersecurity

    Post summary

    The alert details a real‑world Medusa ransomware campaign exploiting zero‑day and recently disclosed vulnerabilities across multiple sectors, with active attacks reported and clear patching recommendations.

    00000130
    273 followersView on X
  • Syed Aquib@syedaquib77
    Active Exploitation

    🚨 Threat Alert: Microsoft links Medusa ransomware affiliate to zero-day attacks (Storm-1175) 📅 Date: 2026-04-06 (Microsoft publication) 📆 Timeline: Active since at least 2023; 2024–2026 saw multiple n-day exploitations and exploit chaining. CVE-2025-10035 (GoAnywhere) and CVE-2026-23760 (SmarterMail) were reportedly exploited ~1 week before public disclosure. Microsoft reports rapid kill‑chains (initial access → exfiltration/encryption within days, sometimes ≤24h). 📍 Location: Australia, United Kingdom, United States (observed) 📌 Attribution: Storm-1175 — China‑based financially motivated cybercrime group; Medusa ransomware affiliate (Microsoft). 📝 Summary: Microsoft Threat Intelligence links high‑velocity Medusa operations to Storm‑1175, an affiliate that quickly weaponizes n‑day and zero‑day flaws in internet‑facing apps to gain access, chain exploits, persist, steal credentials, disable security controls, exfiltrate with tools like Rclone/Bandizip, and deploy Medusa ransomware. Microsoft documents exploitation across numerous CVEs (incl. CVE‑2025‑10035, CVE‑2026‑23760) and use of RMM, living‑off‑the‑land binaries, web shells and PDQ Deployer for distribution. Note: partner/CISA claims (e.g., “300+ critical infrastructure orgs impacted”) are cited by partners and not independently validated here. ⚔️ Attack Details: - Attack Type: Ransomware (Medusa) leveraging zero-day and n-day exploitation - Target: Healthcare; education; professional services; finance; critical infrastructure organizations (partner reporting indicates 300+ impacted in prior campaigns) 📈 Impact: Unauthorized access to internet‑facing systems, credential theft, rapid lateral movement and persistence, security tampering (disabling AV/adding exclusions), large‑scale data exfiltration (Rclone/Bandizip) and widespread file encryption via Medusa causing operational disruption and potential data leaks. Partner reporting attributes incidents affecting 300+ critical‑infrastructure orgs in the U.S.; no consolidated public financial loss figure. 🔗 Related Resources: - https://www.microsoft.com/en-us/security/blog/2026/04/06/storm-1175-focuses-gaze-on-vulnerable-web-facing-assets-in-high-tempo-medusa-ransomware-operations/ - https://www.bleepingcomputer.com/news/security/microsoft-links-medusa-ransomware-affiliate-to-zero-day-attacks/ - https://nvd.nist.gov/vuln/detail/CVE-2025-10035 - https://nvd.nist.gov/vuln/detail/CVE-2026-23760 - https://www.bleepingcomputer.com/news/security/cisa-medusa-ransomware-hit-over-300-critical-infrastructure-orgs/ 🛡️ Recommended Actions: - Patch internet‑facing systems immediately; prioritize CVEs with public exploit activity. - Isolate/limit web‑facing assets (WAF, reverse proxy, DMZ); use attack‑surface monitoring. - Enforce MFA and least privilege; remove shared/local admin creds. - Harden RMM: allow only approved RMM with MFA and strict controls. - Enable tamper protection, attack‑surface reduction rules, Credential Guard, and EDR with automatic disruption. - Monitor for Rclone/Bandizip, PDQ/PSExec/Impacket usage, web shells, unusual account creation and credential dumping. - Maintain offline, tested backups and segmented restore paths. - Hunt for IOCs, hashes and C2 indicators from Microsoft/CISA guidance; follow incident response playbooks if compromise confirmed. 🫨 Attack Vectors: - T1190 - Exploit Public-Facing Application (zero-day and n-day exploitation; examples: CVE-2025-10035, CVE-2026-23760, multiple others since 2023) - T1505.003 (Web Shell) / Web shell deployment for initial foothold and persistence - T1136 - Create Account (creating new local/admin accounts for persistence) - T1078 - Valid Accounts (use of stolen or created accounts for access and lateral movement) - T1021 - Remote Services (use of RMM tools, AnyDesk, ConnectWise ScreenConnect, RDP tunnels for lateral movement and persistence) - T1003 - Credential Dumping (LSASS, NTDS.dit, use of Mimikatz, Veeam password recovery) - T1562 - Impair Defenses (disabling Microsoft Defender, modifying AV exclusions, tamper actions) - T1041 - Exfiltration Over C2 Channel / Use of Rclone and Bandizip for large-scale exfiltration - T1486 - Data Encrypted for Impact (Medusa ransomware deployment) - T1569.002 / T1059 - Windows Command Shell / PsExec and living-off-the-land binaries for remote execution and lateral movement (PDQ Deployer, PsExec, Impacket) 🏷 Tags: #Medusa #Storm-1175 #ransomware #zero-day #n-day #exploits #cybercrime #healthcare #critical-infrastructure #SmarterMail #GoAnywhere #Cybersecurity

    Post summary

    Microsoft’s Threat Intelligence report details that Medusa ransomware affiliates have been exploiting CVE‑2025‑10035 and CVE‑2026‑23760 in the wild, with rapid kill‑chains and widespread damage, and urges immediate patching.

    00000134
    273 followersView on X
  • ThreatCluster@threatcluster
    Active Exploitation

    BREAKING: Microsoft links China-based Storm-1175 to Medusa ransomware campaigns exploiting 16+ vulns including CVE-2025-10035 and CVE-2026-23760, hitting 300+ critical infrastructure orgs. https://threatcluster.io/cluster/storm-1175-exploits-multiple-vulnerabilities-in-medusa-ranso-4c24eb79

    Post summary

    The report highlights that the Storm‑1175/Medusa ransomware campaigns are actively exploiting multiple CVEs, impacting over 300 critical infrastructure organizations, but offers no PoC, exploit code, or mitigation details.

    00000165
    133 followersView on X
  • Israel@f1tym1
    General

    The 24-Hour Blitz: Storm-1175 Weaponizes Zero-Days for High-Velocity Ransomware https://ift.tt/pD1PeIb The post The 24-Hour Blitz: Storm-1175 Weaponizes Zero-Days for High-Velocity Ransomware appeared first on Daily CyberSecurity. Related posts: Critical RCE (CVE-2025-10035…

    Post summary

    The article announces that the CVE‑2025‑10035 RCE has been weaponized by the Storm‑1175 ransomware campaign, but it provides no proof‑of‑concept, patch details, or evidence of active exploitation.

    00000116
    947 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfortragoanywhere_managed_file_transfer---

Explore more