The Register Home Page

back to article Ding ding: Fortra rings the perfect-10 bell over latest GoAnywhere MFT bug

Budding ransomware crooks have another shot at exploiting Fortra's GoAnywhere MFT product now that a new 10/10 severity vulnerability needs patching. The vendor issued an advisory for CVE-2025-10035 on Thursday, saying successful exploitation can potentially lead to command injection. Fortra's advisory states "a …

  1. Anonymous Coward
    Anonymous Coward

    Thank you, editor, for defining MFT in the penultimate paragraph.

    1. Anonymous Coward
      Anonymous Coward

      And thank YOU for pointing out where to find it, for us TL;DR types.

  2. JessicaRabbit Silver badge

    So another piece of software using impossible-to-secure binary serialisation by the sounds of it.

    1. Claptrap314 Silver badge
      Unhappy

      No, and that's the hell of it. It is NOT hard to defend against directory traversal. The fact that errors like these keep popping up while I cannot get a single reply to my resume's is....

  3. David 132 Silver badge
    Happy

    Back to basics

    We should just revert to Kermit or Zmodem for file transfers. Why, back in the day, I transferred dozens of 880KB Amiga floppy images, with nary a single CVE ever encountered!

  4. CyberBunny

    "This isn’t just about GoAnywhere. It’s about a recurring pattern: organizations relying on file transfer tools that put too much of the security burden on the customer. The lesson for CISOs is clear — resilience has to come from the platform’s design, not just from reactive patching." Patrick Spencer, VP, Kiteworks.

  5. CyberBunny

    “CVE-2025-10035 is a reminder that patching alone is not enough. When admin consoles are exposed to the internet, even one flaw can lead to catastrophic exploitation. Our research shows that organisations in the mid-size ‘danger zone’ already face $3–5M breach costs — and flaws like this amplify that risk. Security has to be architectural, with hardened interfaces, sandboxed components, and layered intrusion detection built in from day one.” Patrick Spencer, VP, Kiteworks

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like