FAIL › dossier
GoAnywhere MFT
PRODUCT· dossier confidence 20%
GoAnywhere MFT, a managed file transfer solution, has faced critical vulnerabilities that allowed for remote code execution and command injection. The company has responded to these incidents with forensic analysis and security improvements.
PROFILE
CategoryData ManagementWhat they doGoAnywhere MFT is a managed file transfer (MFT) solution designed to securely exchange files and data over any protocol, network, or platform.
Websitehttps://www.goanywhere.com/ ↗
SECURITY POSTURE
The security posture of GoAnywhere MFT appears to be reactive, with a focus on incident response and recovery following reported vulnerabilities.
Notable failures
- CVE-2025-10035
- CVE-2023-0669
Patterns: Repeated unpatched vulnerabilities leading to remote code execution.
FAILURE HISTORY · 2
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2025-09-29 | CVE-2025-10035 | critical | Fortra GoAnywhere MFT suffered a deserialization vulnerability allowing command injection via forged license signatures, linked to ransomware. |
| 2023-02-10 | CVE-2023-0669 | critical | Fortra GoAnywhere MFT suffered a pre-authentication remote code execution vulnerability due to deserializing attacker-controlled objects in the License Response Servlet. |
DOSSIER SOURCES
- GoAnywhere MFT reviews 2026 - PeerSpot · www.peerspot.com
- Credo Technology Group Holding (CRDO) Company Profile & Description · stockanalysis.com
- Clop ransomware targets Windchill, FlexPLM in data theft attacks · BleepingComputer
- Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with ... · The Hacker News
Open questions: How has the company implemented long-term security improvements to prevent future vulnerabilities?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-27 03:42:52.678483+00:00