Close Menu
TechurzTechurz

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    EV startup Faraday Future paid $7.5M to company tied to founder Jia Yueting

    April 30, 2026

    FDA approval, fundraising, and the reality of building in healthcare according to BioticsAI founder

    April 30, 2026

    SpaceX backer 137 Ventures raises $700M for two growth-stage funds

    April 30, 2026
    Facebook X (Twitter) Instagram
    Trending
    • EV startup Faraday Future paid $7.5M to company tied to founder Jia Yueting
    • FDA approval, fundraising, and the reality of building in healthcare according to BioticsAI founder
    • SpaceX backer 137 Ventures raises $700M for two growth-stage funds
    • Meet Shapes, the app bringing humans and AI into the same group chats
    • Parallel Web Systems hits $2B valuation five months after its last big raise
    • Bill Gurley, Jack Altman back startup Pursuit, which helps companies sell to government
    • Firestorm Labs raises $82M to take drone factories into the field
    • BCI startup Neurable looks to license its ‘mind-reading’ tech for consumer wearables
    Facebook X (Twitter) Instagram Pinterest Vimeo
    TechurzTechurz
    • Home
    • AI
    • Apps
    • News
    • Guides
    • Opinion
    • Reviews
    • Security
    • Startups
    TechurzTechurz
    Home»Security»Fortra Reveals Full Timeline of CVE-2025-10035 Exploitation
    Security

    Fortra Reveals Full Timeline of CVE-2025-10035 Exploitation

    TechurzBy TechurzOctober 10, 2025No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Fortra Reveals Full Timeline of CVE-2025-10035 Exploitation
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Oct 10, 2025Ravie LakshmananVulnerability / Network Security

    Fortra on Thursday revealed the results of its investigation into CVE-2025-10035, a critical security flaw in GoAnywhere Managed File Transfer (MFT) that’s assessed to have come under active exploitation since at least September 11, 2025.

    The company said it began its investigation on September 11 following a “potential vulnerability” reported by a customer, uncovering “potentially suspicious activity” related to the flaw.

    That same day, Fortra said it contacted on-premises customers who were identified as having their GoAnywhere admin console accessible to the public internet and that it notified law enforcement authorities about the incident.

    A hotfix for versions 7.6.x, 7.7.x, and 7.8.x of the software was made available the next day, with full releases incorporating the patch – versions 7.6.3 and 7.8.4 – made available on September 15. Three days later, a CVE for the vulnerability was formally published, it added.

    “The scope of the risk of this vulnerability is limited to customers with an admin console exposed to the public internet,” Fortra said. “Other web-based components of the GoAnywhere architecture are not affected by this vulnerability.”

    However, it conceded that there are a “limited number of reports” of unauthorized activity related to CVE-2025-10035. As additional mitigations, the company is recommending that users restrict admin console access over the internet, as well as enable monitoring and keep software up-to-date.

    CVE-2025-10035 concerns a case of deserialization vulnerability in the License Servlet that could result in command injection without authentication. In a report earlier this week, Microsoft revealed that a threat it tracks as Storm-1175 has been exploiting the flaw since September 11 to deploy Medusa ransomware.

    That said, there is still no clarity on how the threat actors managed to obtain the private keys needed to exploit this vulnerability.

    “The fact that Fortra has now opted to confirm (in their words) ‘unauthorized activity related to CVE-2025-10035’ demonstrates yet again that the vulnerability was not theoretical and that the attacker has somehow circumvented, or satisfied, the cryptographic requirements needed to exploit this vulnerability,” watchTowr CEO and founder Benjamin Harris said.

    CVE202510035 exploitation Fortra full reveals timeline
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleDatenleck bei SonicWall betrifft alle Cloud-Backup-Kunden
    Next Article I compared the best smartwatches by Google and Samsung – here’s how Pixel wins out
    Techurz
    • Website

    Related Posts

    Opinion

    Fusion doesn’t have a normal startup timeline, and investors are fine with that

    April 22, 2026
    Opinion

    EV startup Harbinger reveals a smaller work truck with electric and hybrid variants

    March 11, 2026
    Opinion

    CES 2026: Follow live as NVIDIA, Lego, AMD, Amazon, and more make their big reveals

    January 5, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    College social app Fizz expands into grocery delivery

    September 3, 20252,288 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202516 Views

    The Reason Murderbot’s Tone Feels Off

    May 14, 202512 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    College social app Fizz expands into grocery delivery

    September 3, 20252,288 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202516 Views

    The Reason Murderbot’s Tone Feels Off

    May 14, 202512 Views
    Our Picks

    EV startup Faraday Future paid $7.5M to company tied to founder Jia Yueting

    April 30, 2026

    FDA approval, fundraising, and the reality of building in healthcare according to BioticsAI founder

    April 30, 2026

    SpaceX backer 137 Ventures raises $700M for two growth-stage funds

    April 30, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 techurz. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.