Experts warn that a maximum difficulty goanywhere MFT error is now utilized as a zero day


  • CVE-2025-10035 in GoanyWhere MFT allows critical command injection via License Servlet
  • Utilization began before publication; Watchtowr found credible evidence
  • Users called for patching or isolating systems; Previous deficiencies led to larger CL0P -Ransomware -violations

Goany Where MFT, a popular managed file transfer solution, bears a vulnerability with the maximum severity that is currently being exploited in nature after security researchers Watchtowr Labs claim to have found “credible evidence”.

Fortra (the company behind Goanywhere) recently announced a new security advice that called on customers to patch the CVE-2025-10035.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top