Experts warn a maximum gravity GoanyWhere Mft Flaw is now used as a zero day


  • CVE-2025-10035 at GoanyWhere MFT allows a critical order injection via the license servlet
  • The exploitation began before public disclosure; Watchtowr has found credible evidence in windows
  • Users have asked to correct or isolate systems; Past defects have led to violations of major CL0P ransomware

GoanyWHERE MFT, a popular managed file transfer solution, offers a vulnerability of maximum severity currently operated in the wild after Watchtowr Labs safety researchers claim to have found “credible proofs”.

FORTRA (The company behind GoanyWHERE) recently published a new security notice, urging customers to correct the CVE-2025-10035.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top