Technology NewsTechnology NewsTechnology News
  • Computing
  • AI
  • Robotics
  • Cybersecurity
  • Electric Vehicle
  • Wearables
  • Gaming
  • Space
Reading: Researchers Warn Organizations Patch GoAnywhere MFT Critical Flaw
Share
Font ResizerAa
Technology NewsTechnology News
Font ResizerAa
Search
  • Computing
  • AI
  • Robotics
  • Cybersecurity
  • Electric Vehicle
  • Wearables
  • Gaming
  • Space
Follow US
  • Cookie Policy (EU)
  • Contact
  • About
© 2025 NEWSLINKER - Powered by LK SOFTWARE
Cybersecurity

Researchers Warn Organizations Patch GoAnywhere MFT Critical Flaw

Highlights

  • GoAnywhere MFT faces a maximum-severity vulnerability affecting sensitive file transfers.

  • Attackers could exploit the flaw without authentication, posing serious risk to organizations.

  • Fortra released a patch, and experts urge rapid implementation and review.

Ethan Moreno
Last updated: 20 September, 2025 - 12:19 am 12:19 am
Ethan Moreno 3 hours ago
Share
SHARE

Organizations relying on secure file transfers are facing new security concerns with the discovery of a major vulnerability in GoAnywhere MFT, a managed file-transfer service from Fortra. As businesses increasingly depend on automated systems to handle sensitive data flows, the risks associated with cybersecurity flaws are growing. Experts urge proactive defense, emphasizing the lessons learned from earlier incidents tied to similar services such as MOVEit, which saw global impacts. Many firms, including those from the Fortune 500, rely on GoAnywhere, heightening the stakes for a timely and coordinated response.

Contents
How Does the GoAnywhere MFT Vulnerability Work?Have There Been Any Exploits So Far?How Are Companies Responding to the Discovery?

When the MOVEit Transfer vulnerability was disclosed in 2023, mass exploitation resulted in serious data breaches across thousands of organizations. The sheer scale of the MOVEit event demonstrated the attractiveness of file transfer services as a target to cybercriminals. While that incident led to swift adoption of upgrades and training by many customers, some organizations did not apply patches quickly enough, leading to prolonged exposure. With the new GoAnywhere MFT weakness bearing technical likeness to earlier exploited flaws, risk analysts are closely monitoring to see if prior lessons translate to faster mitigation this time.

How Does the GoAnywhere MFT Vulnerability Work?

The newly identified flaw, tracked as CVE-2025-10035, allows an attacker who forges a valid license response signature to gain the ability to execute unauthorized commands on the system. This vulnerability affects GoAnywhere MFT’s deserialization process, potentially opening avenues for command injection. Notably, the defect does not require authentication, making it particularly accessible for unauthorized actors if an admin console is exposed online.

Have There Been Any Exploits So Far?

Security firms monitoring the threat landscape report no public evidence of exploitation at this time, but concern remains high due to previous patterns. Historical attacks, particularly those involving the Clop ransomware group, have capitalized on similar vulnerabilities in file-transfer software such as CVE-2023-0669. Industry observers predict it is a matter of time before malicious actors attempt to exploit GoAnywhere MFT, especially given the high CVSS score and the lack of an authentication requirement.

How Are Companies Responding to the Discovery?

Fortra, the developer behind GoAnywhere, discovered the flaw during a regular security review on September 11 and responded with the release of a patch and customer mitigation guidance.

“We identified that GoAnywhere customers with an admin console accessible over the internet could be vulnerable to unauthorized third-party exposure,”

explained Jessica Ryan, public relations manager at Fortra. Customers were swiftly notified with recommendations designed to limit risk and assist in resolving the issue.

“We immediately developed a patch and offered customers mitigation guidance to help resolve the issue,”

added Ryan, underscoring the urgency of the company’s response.

Threats to managed file-transfer products such as GoAnywhere MFT have become increasingly frequent, with multiple vulnerabilities from Fortra listed in the Cybersecurity and Infrastructure Security Agency’s known exploited vulnerabilities catalog within a short span. The recurrence of similar flaws highlights persistent security challenges within the sector. For organizations, the swift patching of critical systems and reviewing external exposure remain essential steps in reducing the threat surface. Security researchers remind system administrators that even the best patch management programs cannot be fully effective if vulnerabilities are exploited covertly before detection, and that compromised systems may require further investigation and remediation beyond patching.

You can follow us on Youtube, Telegram, Facebook, Linkedin, Twitter ( X ), Mastodon and Bluesky

You Might Also Like

Trump Administration Weighs Faster Deadlines for Quantum Security

Defense Department Sets Ambitious 25-Day Goal for Cybersecurity Hiring

UK Authorities Arrest Teens Linked to Global Scattered Spider Cyberattacks

SonicWall Confirms Cloud Portal Breach Exposes Firewall Configurations

Microsoft Seizes Hundreds of Phishing Domains in Global Takedown

Share This Article
Facebook Twitter Copy Link Print
Ethan Moreno
By Ethan Moreno
Ethan Moreno, a 35-year-old California resident, is a media graduate. Recognized for his extensive media knowledge and sharp editing skills, Ethan is a passionate professional dedicated to improving the accuracy and quality of news. Specializing in digital media, Moreno keeps abreast of technology, science and new media trends to shape content strategies.
Previous Article Developers Guide AI Tools as Vibe Coding Reshapes Software Creation
Next Article CarbonSix Deploys SigmaKit to Simplify Robot Imitation Learning in Factories

Stay Connected

6.2kLike
8kFollow
2.3kSubscribe
1.7kFollow

Latest News

Surgeons Embrace Robotics and AI in Operating Rooms
AI
CarbonSix Deploys SigmaKit to Simplify Robot Imitation Learning in Factories
AI
Developers Guide AI Tools as Vibe Coding Reshapes Software Creation
AI Technology
Tesla Tackles Recurring Autopilot Camera Flaws, Promises Solutions
Electric Vehicle
Tesla Faces Leadership Shift as Optimus AI Head Joins Meta
Electric Vehicle
NEWSLINKER – your premier source for the latest updates in ai, robotics, electric vehicle, gaming, and technology. We are dedicated to bringing you the most accurate, timely, and engaging content from across these dynamic industries. Join us on our journey of discovery and stay informed in this ever-evolving digital age.

ARTIFICAL INTELLIGENCE

  • Can Artificial Intelligence Achieve Consciousness?
  • What is Artificial Intelligence (AI)?
  • How does Artificial Intelligence Work?
  • Will AI Take Over the World?
  • What Is OpenAI?
  • What is Artifical General Intelligence?

ELECTRIC VEHICLE

  • What is Electric Vehicle in Simple Words?
  • How do Electric Cars Work?
  • What is the Advantage and Disadvantage of Electric Cars?
  • Is Electric Car the Future?

RESEARCH

  • Robotics Market Research & Report
  • Everything you need to know about IoT
  • What Is Wearable Technology?
  • What is FANUC Robotics?
  • What is Anthropic AI?
Technology NewsTechnology News
Follow US
About Us   -  Cookie Policy   -   Contact

© 2025 NEWSLINKER. Powered by LK SOFTWARE
Welcome Back!

Sign in to your account

Register Lost your password?