• News/
  • https://www.theregister.com/2025/09/26/an_apts_playground_goanywhere_perfect10/

‘An attacker's playground:’ Crims exploit GoAnywhere perfect-10 bug

The Register
·
Connor Jones
·
Published Sep 26, 2025
·
Updated

Security researchers have confirmed that threat actors have exploited the maximum-severity vulnerability affecting Fortra's GoAnywhere managed file transfer (MFT), and chastised the vendor for a lack of transparency. The experts over at watchTowr, never ones to mince their words, described the revelation as "an increasingly disappointing situation," criticizing Fortra for not sharing enough details about the exploitation status of CVE-2025-10035. The Register reported on the vulnerability last week after Fortra disclosed it on September 18. In our story, we noted that Fortra did not confirm whether it was actively being exploited under its "Am I Impacted?" section. "Exploitation of this vulnerability is highly dependent upon systems being externally exposed to the internet," it said at the time. The watchTowr researchers Xeeted that it was likely that exploits had already been successful, and in their latest blog, they said that they received evidence of attacks using the vulnerability on September 10. According to watchTowr's findings, attackers trigger the pre-auth deserialization bug to achieve remote code execution (RCE) capability, then create backdoor admin accounts and web users before executing multiple follow-on payloads. "Unfortunately, the picture now painted allows for evidence-based confidence in the concern that Fortra's 'Am I Impacted?' section probably was not Fortra attempting to be overly helpful, but a thinly veiled way of sharing 'Indicators of Compromise,...

Read full article

Affected Software

1 affected component
Fortra GoAnywhere

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the exploitation of a critical vulnerability in Fortra's GoAnywhere managed file transfer software.

2

What security implications are discussed?

The article highlights the severity of the vulnerability and the potential for threat actors to exploit it for malicious activities.

3

What products or software are affected?

The affected product mentioned in the article is Fortra's GoAnywhere managed file transfer software.

4

What actions are being criticized in the article?

The article criticizes Fortra for their lack of transparency regarding the vulnerability and its exploitation.

5

Who are the main actors involved in the security incident?

The main actors involved are threat actors exploiting the vulnerability and security researchers investigating the incident.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203