Close Menu
TechurzTechurz

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Digg lays off staff and shuts down app as company retools

    March 13, 2026

    The biggest AI stories of the year (so far)

    March 13, 2026

    The $32B acquisition that one VC is calling the ‘Deal of the Decade’

    March 13, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Digg lays off staff and shuts down app as company retools
    • The biggest AI stories of the year (so far)
    • The $32B acquisition that one VC is calling the ‘Deal of the Decade’
    • Before quantum computing arrives, this startup wants enterprises already running on it
    • Sales automation startup Rox AI hits $1.2B valuation, sources say
    • Humanoid robotics maker Sunday reaches $1.15B valuation to build household robots
    • Humanoid maker Sunday reaches $1.15 billion valuation to build household robots
    • Gumloop lands $50M from Benchmark to turn every employee into an AI agent builder
    Facebook X (Twitter) Instagram Pinterest Vimeo
    TechurzTechurz
    • Home
    • AI
    • Apps
    • News
    • Guides
    • Opinion
    • Reviews
    • Security
    • Startups
    TechurzTechurz
    Home»Security»Fortra Reveals Full Timeline of CVE-2025-10035 Exploitation
    Security

    Fortra Reveals Full Timeline of CVE-2025-10035 Exploitation

    TechurzBy TechurzOctober 10, 2025No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Fortra Reveals Full Timeline of CVE-2025-10035 Exploitation
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Oct 10, 2025Ravie LakshmananVulnerability / Network Security

    Fortra on Thursday revealed the results of its investigation into CVE-2025-10035, a critical security flaw in GoAnywhere Managed File Transfer (MFT) that’s assessed to have come under active exploitation since at least September 11, 2025.

    The company said it began its investigation on September 11 following a “potential vulnerability” reported by a customer, uncovering “potentially suspicious activity” related to the flaw.

    That same day, Fortra said it contacted on-premises customers who were identified as having their GoAnywhere admin console accessible to the public internet and that it notified law enforcement authorities about the incident.

    A hotfix for versions 7.6.x, 7.7.x, and 7.8.x of the software was made available the next day, with full releases incorporating the patch – versions 7.6.3 and 7.8.4 – made available on September 15. Three days later, a CVE for the vulnerability was formally published, it added.

    “The scope of the risk of this vulnerability is limited to customers with an admin console exposed to the public internet,” Fortra said. “Other web-based components of the GoAnywhere architecture are not affected by this vulnerability.”

    However, it conceded that there are a “limited number of reports” of unauthorized activity related to CVE-2025-10035. As additional mitigations, the company is recommending that users restrict admin console access over the internet, as well as enable monitoring and keep software up-to-date.

    CVE-2025-10035 concerns a case of deserialization vulnerability in the License Servlet that could result in command injection without authentication. In a report earlier this week, Microsoft revealed that a threat it tracks as Storm-1175 has been exploiting the flaw since September 11 to deploy Medusa ransomware.

    That said, there is still no clarity on how the threat actors managed to obtain the private keys needed to exploit this vulnerability.

    “The fact that Fortra has now opted to confirm (in their words) ‘unauthorized activity related to CVE-2025-10035’ demonstrates yet again that the vulnerability was not theoretical and that the attacker has somehow circumvented, or satisfied, the cryptographic requirements needed to exploit this vulnerability,” watchTowr CEO and founder Benjamin Harris said.

    CVE202510035 exploitation Fortra full reveals timeline
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleDatenleck bei SonicWall betrifft alle Cloud-Backup-Kunden
    Next Article I compared the best smartwatches by Google and Samsung – here’s how Pixel wins out
    Techurz
    • Website

    Related Posts

    Opinion

    EV startup Harbinger reveals a smaller work truck with electric and hybrid variants

    March 11, 2026
    Opinion

    CES 2026: Follow live as NVIDIA, Lego, AMD, Amazon, and more make their big reveals

    January 5, 2026
    Security

    AI is becoming introspective – and that ‘should be monitored carefully,’ warns Anthropic

    November 3, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    College social app Fizz expands into grocery delivery

    September 3, 20252,286 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202514 Views

    The Reason Murderbot’s Tone Feels Off

    May 14, 202511 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    College social app Fizz expands into grocery delivery

    September 3, 20252,286 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202514 Views

    The Reason Murderbot’s Tone Feels Off

    May 14, 202511 Views
    Our Picks

    Digg lays off staff and shuts down app as company retools

    March 13, 2026

    The biggest AI stories of the year (so far)

    March 13, 2026

    The $32B acquisition that one VC is calling the ‘Deal of the Decade’

    March 13, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 techurz. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.