Out-of-Band / Urgent Remediation
Listed in the CISA KEV catalog, and an EPSS probability of 0.998.
A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.
Vulnerability type: CWE-77 | CWE-502 — Deserialization of untrusted data
Impacted software or hardware
- goanywhere managed file transfer Software < 7.6.3, >= 7.7.0 < 7.8.4
Patch status: Patch or fixed version identified
Fixed versions: goanywhere managed file transfer: update to 7.6.3 or later | goanywhere managed file transfer: update to 7.8.4 or later
Remediation: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation basis: CISA KEV required action
CISA KEV: known exploited. Remediation due 2025-10-20. Known ransomware campaign use: Known.
Research this vulnerability
- NIST NVD — Scores, weaknesses, products, and references
- CVE.org — Authoritative CVE Program record
- CISA KEV — Known exploitation and federal remediation action
- Tenable — Detection plugins and Tenable analysis
- Rapid7 — Threat, exploit, and remediation research
- GitHub Advisory — Open-source package advisories
- Snyk — Package versions and available fixes