Skip to content
COOEY

FAIL › dossier

GoAnywhere MFT

PRODUCT

· dossier confidence 20%

GoAnywhere MFT, a managed file transfer solution, has faced critical vulnerabilities that allowed for remote code execution and command injection. The company has responded to these incidents with forensic analysis and security improvements.

PROFILE
CategoryData ManagementWhat they doGoAnywhere MFT is a managed file transfer (MFT) solution designed to securely exchange files and data over any protocol, network, or platform. Websitehttps://www.goanywhere.com/ ↗
SECURITY POSTURE

The security posture of GoAnywhere MFT appears to be reactive, with a focus on incident response and recovery following reported vulnerabilities.

Notable failures
  • CVE-2025-10035
  • CVE-2023-0669
Patterns: Repeated unpatched vulnerabilities leading to remote code execution.
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2025-09-29 CVE-2025-10035 critical Fortra GoAnywhere MFT suffered a deserialization vulnerability allowing command injection via forged license signatures, linked to ransomware.
2023-02-10 CVE-2023-0669 critical Fortra GoAnywhere MFT suffered a pre-authentication remote code execution vulnerability due to deserializing attacker-controlled objects in the License Response Servlet.
Open questions: How has the company implemented long-term security improvements to prevent future vulnerabilities?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-27 03:42:52.678483+00:00