Microsoft warns that a critical GoAnywhere security bug is being exploited by a ransomware gang, so be on guard


  • CVE-2025-10035 in GoAnywhere MFT is exploited by the Storm-1175 ransomware group
  • The vulnerability allows unauthenticated remote code execution; Medusa ransomware deployed in at least one case
  • Patch released September 18; over 500 instances remain exposed, requiring immediate upgrades or mitigations

Microsoft warns that a ransomware group is exploiting a recently discovered maximum severity vulnerability in GoAnywhere Managed File Transfer (MFT).

Fortra recently said it discovered and fixed a deserialization vulnerability in the licensing servlet of GoAnywhere MFT, a tool that helps businesses send and receive files securely.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top