Executive Summary
In June 2024, Fortra disclosed a critical vulnerability (CVE-2024-XXXX) in its GoAnywhere Managed File Transfer (MFT) product’s License Servlet, enabling unauthenticated attackers to execute system commands remotely via command injection. Researchers discovered that by submitting crafted requests to the vulnerable servlet, attackers could gain full control of affected servers. No authentication was required, significantly increasing the risk of exploitation. Fortra released immediate security updates and guidance after reports of active exploitation attempts surfaced. Impacted organizations primarily included enterprises leveraging GoAnywhere MFT for secure file transfers, resulting in heightened risk of data exfiltration and business disruption.
This incident underscores the ongoing importance of timely patch management, especially for widely used secure transfer solutions. The vulnerability’s ease of exploitation and criticality reflects trends of attackers targeting third-party file transfer products—often for extortion or ransomware campaigns—prompting renewed regulatory and industry scrutiny.
Why This Matters Now
Zero-day vulnerabilities in secure file transfer solutions remain a top target for attackers due to their role in business-critical operations and the sensitive data handled. With reports of active exploits and risk of data breaches across industries, immediate patching is essential to prevent severe operational and reputational impact.
Attack Path Analysis
The attack began with attackers exploiting a command injection vulnerability in GoAnywhere MFT's License Servlet, gaining initial foothold on the application. They likely escalated privileges to obtain broader system access, enabling deeper compromise. With these privileges, attackers moved laterally within the cloud or hybrid infrastructure, seeking sensitive data or adjacent workloads. They established command and control channels for persistent communication and potential remote manipulation. Data exfiltration likely followed, with sensitive files being transferred over outbound channels. Finally, the impact phase could include data theft, extortion, or operational disruption of affected systems.
Kill Chain Progression
Initial Compromise
Description
Attackers exploited a command injection vulnerability (CVE) in GoAnywhere MFT's License Servlet to gain unauthorized access.
Related CVEs
CVE-2025-10035
CVSS 10A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.
Affected Products:
Fortra GoAnywhere MFT – < 7.8.4
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Command and Scripting Interpreter
Exploitation for Client Execution
Indicator Removal on Host
Impair Defenses
OS Credential Dumping
Exfiltration Over Alternative Protocol
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Public-Facing Web Application Vulnerability Management
Control ID: 6.2.4
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Art. 8
CISA ZTMM 2.0 – Automated Vulnerability and Patch Management
Control ID: Pillar: Application and Workload, Section: Vulnerability Management
NIS2 Directive – Cybersecurity Risk Management and Reporting
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
GoAnywhere MFT command injection vulnerability threatens secure file transfers, potentially compromising sensitive financial data and violating PCI/regulatory compliance requirements.
Health Care / Life Sciences
Maximum severity flaw in file transfer systems risks patient data exposure, HIPAA violations, and disruption of critical healthcare data exchanges.
Government Administration
Application vulnerability in managed file transfer solutions threatens government data integrity, inter-agency communications, and sensitive information security protocols.
Information Technology/IT
License Servlet command injection flaw impacts IT service providers managing client file transfers, requiring immediate patching to prevent widespread exploitation.
Sources
- Fortra warns of max severity flaw in GoAnywhere MFT’s License Servlethttps://www.bleepingcomputer.com/news/security/fortra-warns-of-max-severity-flaw-in-goanywhere-mfts-license-servlet/Verified
- Deserialization Vulnerability in GoAnywhere MFT's License Servlethttps://www.fortra.com/security/advisories/product-security/fi-2025-012Verified
- CVE-2025-10035 Detailhttps://nvd.nist.gov/vuln/detail/CVE-2025-10035Verified
- Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerabilityhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-10035Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust segmentation, egress filtering, inline threat detection, and workload-to-workload isolation would have constrained or prevented the attacker's progression across key stages of the kill chain. CNSF capabilities would have limited lateral movement, detected C2 channels, enforced least privilege, and blocked data exfiltration.
Control: Inline IPS (Suricata)
Mitigation: Prevents or detects exploitation attempts at the perimeter.
Control: Zero Trust Segmentation
Mitigation: Prevents attackers from accessing sensitive roles or system identities.
Control: East-West Traffic Security
Mitigation: Blocks unauthorized workload-to-workload communication.
Control: Egress Security & Policy Enforcement
Mitigation: Prevents unauthorized outbound communications and detects anomalous C2 traffic.
Control: Multicloud Visibility & Control
Mitigation: Detects and blocks anomalous large data transfers and exfiltration attempts.
Alerts and enables rapid response to suspicious or destructive actions.
Impact at a Glance
Affected Business Functions
- File Transfer Operations
- Data Exchange Services
Estimated downtime: 3 days
Estimated loss: $500,000
Potential exposure of sensitive data due to unauthorized command execution.
Recommended Actions
Key Takeaways & Next Steps
- • Deploy inline IPS with up-to-date signatures to block exploitation of published vulnerabilities in key applications and services.
- • Enforce Zero Trust segmentation and least privilege policies to restrict lateral movement and contain breaches at the workload level.
- • Enable comprehensive east-west and egress filtering to prevent unauthorized movement and outbound data exfiltration.
- • Maintain centralized visibility and anomaly detection across all cloud regions and workloads for early detection of suspicious behaviors.
- • Regularly review and patch third-party and managed file transfer solutions immediately upon disclosure of critical vulnerabilities.



