<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — Fortra</title><description>Actively exploited vulnerabilities affecting Fortra products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/fortra.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2025-10035 — Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-10035</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-10035</guid><description>GoAnywhere MFT, a widely-used managed file transfer product, contains a deserialization flaw that can be exploited by an attacker who possesses a validly forged license response signature. If exploited, this allows arbitrary objects to be deserialized and can lead to command injection — effectively giving an attacker the ability to run commands on the affected system. This vulnerability is already associated with known ransomware activity, making rapid response critical for any organization running this product.</description><pubDate>Mon, 29 Sep 2025 00:00:00 GMT</pubDate><category>Fortra</category><category>GoAnywhere MFT</category></item></channel></rss>