Find notable cyber news and cases, enriched with sources, timelines, and signals.
Vulnerability Campaign ×2 Exploitation Wave Security Patch Release

GoAnywhere MFT exploitation after CVE-2025-10035

Updated 07.04.2026 23:15
Case score 73
Members 5 First seen 19.09.2025 17:20 Latest activity 07.04.2026 23:15

Overview

**Fortra GoAnywhere MFT** exploitation of **CVE-2025-10035** moved quickly from vendor investigation into an active ransomware story. The flaw is a critical deserialization issue in the **License Servlet** that matters most when the **Admin Console** is exposed to the public internet, and Microsoft tied abuse of it to **Storm-1175** and **Medusa ransomware**. Fortra said it investigated beginning on September 11, 2025, notified affected customers and law enforcement, and released patched versions later in September. Available evidence does not quantify the full scope of compromise, but it does show enough unauthorized activity and post-exploitation tradecraft to keep exposed deployments on urgent watch.
Latest development Open development history 4 earlier developments Microsoft discloses Storm-1175's high-tempo Medusa ransomware campaign Microsoft disclosed that Storm-1175 has been weaponizing n-day and zero-day exploits in high-tempo Medusa ransomware attacks for the past three years, exploiting at least 16 vulnerabilities since 2023 and including CVE-2025-10035 in GoAnywhere Managed File Transfer. Microsoft said the activity has recently affected healthcare, education, professional services, and finance organizations in Australia, the UK, and the US, with the group typically racing between vulnerability disclosure and patch adoption.
  1. Earlier development

    Fortra identifies CVE-2025-10035 in GoAnywhere MFT

    During a security check on September 11, 2025, Fortra identified that GoAnywhere customers with an Admin Console accessible over the internet could face unauthorized third-party exposure from a deserialization flaw in the License Servlet, where a validly forged license response signature could let an actor deserialize an arbitrary actor-controlled object and possibly reach command injection.

  2. Earlier development

    Storm-1175 high-velocity Medusa ransomware campaign

    Microsoft says Storm-1175, a China-based financially motivated cybercriminal group linked to Medusa ransomware, is rapidly weaponizing n-day and zero-day flaws, sometimes within 24 hours and sometimes before patches are released. The operators chain multiple exploits with new user account creation, remote monitoring and management software deployment, credential theft, and security software disabling to move from initial access to data exfiltration and Medusa ransomware deployment. Recent activity has affected healthcare, education, professional services, and finance organizations in Australia, the United Kingdom, and the United States, with exploited products including GoAnywhere MFT, SmarterMail, Microsoft Exchange, Papercut, Ivanti Connect Secure and Policy Secure, ConnectWise ScreenConnect, JetBrains TeamCity, SimpleHelp, CrushFTP, and BeyondTrust.

  3. Earlier development

    Storm-1175 exploits CVE-2025-10035 in GoAnywhere for Medusa ransomware

    Microsoft attributed Storm-1175 to exploiting CVE-2025-10035 in Fortra GoAnywhere MFT to gain initial access and deploy Medusa ransomware against affected GoAnywhere environments. The critical deserialization flaw can permit unauthenticated command injection and potential RCE, and Microsoft said activity has been observed since September 10-11, 2025. The post-exploitation chain includes dropping SimpleHelp and MeshAgent, creating .jsp files in GoAnywhere MFT directories, using mstsc.exe for lateral movement, running Rclone for exfiltration, and using a Cloudflare tunnel for C2.

  4. Earlier development

    Fortra releases GoAnywhere MFT patches for CVE-2025-10035

    On September 19, 2025, Fortra released GoAnywhere MFT 7.8.4 and Sustain Release 7.6.3 to patch CVE-2025-10035 and advised administrators to remove public access from the GoAnywhere Admin Console if they cannot upgrade immediately, because exploitation is highly dependent on systems being externally exposed to the internet.

Signals

Impact signals
Exploitation
CVEs/products
Geographic context
Remediation
Status
Threat context
Data exposure

Threat actor context

4 listed

Malware & tooling context

4 families · 3 tools
Tools

Technical intelligence

Existing Case data

Member happenings

Vulnerability GoAnywhere MFT License Servlet deserialization flaw (CVE-2025-10035)
Updated 19.09.2025 17:20 Lead Contribution 66
CVSS 10.0 Critical Data Status Exposed/Unsecured Patch Patch Available

**Fortra GoAnywhere MFT** vulnerability **CVE-2025-10035** is a **critical deserialization flaw** in the **License Servlet** that can lead to **command injection** and is assessed as **actively exploited since at least September 11, 2025**. **Fortra** said the risk is limited to systems with the **Admin Console exposed to the public internet**, notified affected on-premises customers and **law enforcement**, and released fixes in **September 2025**. **Microsoft** linked exploitation to **Storm-1175** and said the flaw was used to deploy **Medusa ransomware**.

Exploitation Wave Fortra GoAnywhere MFT CVE-2025-10035 active exploitation wave
Updated 07.10.2025 11:45 Scoring Support Contribution 2
Exploitation Active Exploitation CVSS 10.0 Critical Patch Patch Available

**CVE-2025-10035** in **Fortra GoAnywhere Managed File Transfer (MFT)** is being **actively exploited** in **ransomware attacks** against systems with the **admin console exposed to the public internet**. **Fortra** said the flaw is a **critical deserialization vulnerability** in the **License Servlet** and confirmed **unauthorized activity** tied to the issue, while **Microsoft** linked the abuse to **Storm-1175** and **Medusa ransomware**. The vendor investigated starting **September 11, 2025**, notified affected on-premises customers and law enforcement, and released a **hotfix on September 12** followed by full patched versions on **September 15**.

Campaign Storm-1175 high-tempo Medusa ransomware campaign
Updated 07.04.2026 13:02 Scoring Support Contribution 2
Objective Financial Extortion Campaign Active

**Storm-1175** is running a **high-tempo Medusa ransomware campaign** that has repeatedly exploited **n-day and zero-day flaws** to gain initial access before patching closes the window. Microsoft tied the group to **CVE-2025-10035** in **Fortra GoAnywhere MFT**, a **critical deserialization bug** that can enable **unauthenticated command injection** and potential **RCE**, with activity observed since **September 10-11, 2025**. The campaign has affected **healthcare**, **education**, **professional services**, and **finance** organizations in **Australia**, the **UK**, and the **US**, and post-exploitation activity has included **SimpleHelp**, **MeshAgent**, **mstsc.exe**, **Rclone**, and **Cloudflare tunnel** usage.

Campaign Storm-1175 high-velocity exploit campaign
Updated 06.04.2026 19:56 Scoring Support Contribution 2
Objective Financial Extortion Campaign Active Patch Patch Available

**Storm-1175** is running a **high-velocity exploit campaign** that rapidly turns access into **Medusa ransomware** deployment, creating risk of **data exfiltration** and encrypted outages. The group is now tied to **CVE-2025-10035** in **Fortra GoAnywhere Managed File Transfer (MFT)**, a **critical deserialization flaw** with **CVSS 10.0** that Microsoft says is being **actively exploited** in ransomware attacks. Microsoft says **Storm-1175** first used the flaw as a **zero day** on **September 11**, and Fortra patched it on **September 18**. Post-exploitation activity included **SimpleHelp**, **MeshAgent**, **mstsc.exe**, **Rclone**, lateral movement, and a **Cloudflare tunnel** for command-and-control.

Security Patch Release Fortra GoAnywhere MFT security update (CVE-2025-10035)
Updated 19.09.2025 17:20 Context
CVSS 10.0 Critical Urgency Immediate Patch Patch Available

**CVE-2025-10035** in **Fortra GoAnywhere Managed File Transfer (MFT)** is a **critical deserialization flaw** in the **License Servlet** that can enable **unauthenticated command injection** on systems with an **admin console exposed to the public internet**. Fortra said it found potentially suspicious activity after a report on **September 11, 2025**, notified affected on-premises customers and law enforcement, and released a **hotfix** for **7.6.x, 7.7.x, and 7.8.x** the next day, followed by full patched releases **7.6.3** and **7.8.4** on **September 15**. Fortra also said it has received a **limited number of reports** of unauthorized activity, while Microsoft tied exploitation to **Storm-1175** and **Medusa ransomware**.