Executive Summary
In September 2025, a maximum severity zero-day vulnerability (CVE-2025-10035) in Fortra’s GoAnywhere Managed File Transfer (MFT) platform was actively exploited in the wild. Attackers remotely injected commands via a deserialization flaw in the License Servlet, requiring only a forged license response signature to achieve pre-authentication remote code execution. The breach timeline reveals attackers gained access at least a week before public disclosure, establishing persistence via a backdoor admin account and deploying secondary payloads like SimpleHelp for ongoing access, with evidence of lateral movement reconnaissance.
The incident underscores the increasing sophistication and rapid weaponization of zero-day exploits targeting widely used enterprise file transfer solutions. With high-profile breaches tied to vulnerabilities in GoAnywhere, pressure is mounting for organizations to reassess their exposure and incident response practices amid a sharp uptick in exploit automation and data exfiltration attacks.
Why This Matters Now
This breach highlights the urgent need to swiftly address zero-day vulnerabilities in critical B2B applications, especially those exposed to the internet. Organizations relying on managed file transfer tools face heightened risk from attackers exploiting unpatched flaws to gain privileged access and move laterally, amplifying both operational impact and regulatory exposure.
Attack Path Analysis
Attackers exploited a zero-day deserialization vulnerability (CVE-2025-10035) in the GoAnywhere MFT Admin Console to gain unauthenticated remote command execution. They created a backdoor admin account, escalating privileges and enabling persistent access. Using this account, they created additional users and assessed permissions for further movement. The adversaries uploaded and executed multiple payloads, including remote access software, establishing command and control. Sensitive account and group information was gathered and exfiltrated for lateral movement and data theft. The attack's impact included persistent compromise of the environment and potential staging for further data theft or ransomware.
Kill Chain Progression
Initial Compromise
Description
The attacker exploited a zero-day pre-auth deserialization flaw (CVE-2025-10035) in the GoAnywhere MFT admin interface exposed to the internet, achieving unauthenticated remote command execution.
Related CVEs
CVE-2025-10035
CVSS 9.8A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.
Affected Products:
Fortra GoAnywhere MFT – < 7.8.4, < 7.6.3
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Process Injection
Windows Management Instrumentation
Create Account
Valid Accounts
Ingress Tool Transfer
Data from Local System
Automated Exfiltration
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS v4.0 – Security of All System Components and Software
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (Digital Operational Resilience Act) – ICT Risk Management Framework
Control ID: Art. 5
CISA Zero Trust Maturity Model (ZTMM) 2.0 – Enforce Strong Identity and Least Privilege
Control ID: Identity Pillar – Authentication and Access Control
NIS2 Directive – Vulnerability Handling and Disclosure
Control ID: Article 21(2)(d)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
GoAnywhere MFT zero-day exploitation poses critical risk to secure file transfers, regulatory compliance, and sensitive financial data protection requiring immediate patching.
Health Care / Life Sciences
Maximum severity vulnerability threatens HIPAA compliance through compromised patient data transfers, creating backdoor access and potential regulatory violations across healthcare networks.
Government Administration
Zero-day deserialization flaw enables unauthenticated remote command execution, compromising secure government file transfers and creating persistent backdoor access for threat actors.
Legal Services
CVE-2025-10035 exploitation jeopardizes confidential client file transfers and attorney-client privilege through remote access tools and secondary payload deployment on legal networks.
Sources
- Maximum severity GoAnywhere MFT flaw exploited as zero dayhttps://www.bleepingcomputer.com/news/security/maximum-severity-goanywhere-mft-flaw-exploited-as-zero-day/Verified
- CISA Adds Five Known Exploited Vulnerabilities to Cataloghttps://www.cisa.gov/news-events/alerts/2025/09/29/cisa-adds-five-known-exploited-vulnerabilities-catalogVerified
- Fortra Security Advisory FI-2025-012https://www.fortra.com/security/advisories/product-security/fi-2025-012Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust segmentation, granular east-west controls, and enforced egress policies could have limited the exploitation scope, contained attacker movement, and detected or blocked key stages. Microsegmentation and centralized visibility would have restricted unauthorized admin access, flagged anomalous behavior, and prevented data exfiltration via outbound channels.
Control: Cloud Firewall (ACF)
Mitigation: Blocked direct access to the GoAnywhere Admin Console from untrusted external sources.
Control: Zero Trust Segmentation
Mitigation: Limited ability to escalate privileges by enforcing identity-based least privilege policies.
Control: East-West Traffic Security
Mitigation: Contained lateral movement by monitoring and restricting unauthorized workload-to-workload communication.
Control: Inline IPS (Suricata)
Mitigation: Detected and blocked known-malicious payloads and remote access connections.
Control: Egress Security & Policy Enforcement
Mitigation: Prevented unauthorized outbound data exfiltration and flagged abnormal outbound traffic.
Detected persistent abnormal activity, enabling rapid response to limit business impact.
Impact at a Glance
Affected Business Functions
- File Transfer Operations
- Data Exchange Processes
Estimated downtime: 5 days
Estimated loss: $500,000
Potential exposure of sensitive data due to unauthorized access facilitated by the vulnerability.
Recommended Actions
Key Takeaways & Next Steps
- • Immediately remove public internet exposure for administrative interfaces using centralized network firewall controls.
- • Apply zero trust segmentation and identity-based policies to restrict admin and workload access to least privilege.
- • Enforce east-west traffic monitoring and microsegmentation to detect and prevent lateral movement.
- • Enable inline threat detection and egress enforcement to block malware uploads and unauthorized data exfiltration.
- • Continuously audit and baseline account activity to catch abnormal privilege escalation and persistent access attempts.



