References https://www.fortra.com/security/advisories/product-security/fi-2025-012 https://nvd.nist.gov/vuln/detail/CVE-2025-10035 https://www.cve.org/cverecord?id=CVE-2025-10035 https://labs.watchtowr.com/is-this-bad-this-feels-bad-goanywhere-cve-2025-10035/ https://www.microsoft.com/en-us/security/blog/2025/10/06/investigating-active-exploitation-of-cve-2025-10035-goanywhere-managed-file-transfer-vulnerability/ https://www.runzero.com/blog/fortra-goanywhere-mft/ https://www.goanywhere.com/blog/summary-investigation-related-cve-2025-10035 https://labs.watchtowr.com/is-this-bad-this-feels-bad-goanywhere-cve-2025-10035/ https://fortiguard.fortinet.com/outbreak-alert/goanywhere-mft-attack
Related Vulnerabilities关于U8cloud所有版本CodeSyncServlet接口存在任意文件下载漏洞的安全通告PoCCVE-2017-7504: JBossMQ HTTP Invocation Layer (HTTPServerILServlet) - Unauthenticated Java Deserialization用友U8Cloud MailApproveServlet存在SQL注入漏洞用友U8Cloud /ServiceDispatcherServlet 文件上传漏洞用友 U8cloud /service/XChangeServlet SQL 注入漏洞关于NC Cloud及YonBIP高级版系统的datacollectservlet接口漏洞安全通告关于U8cloud所有版本XChangeServlet接口存在SQL注入漏洞的安全公告用友 U8 Cloud ThinApproveServlet SQL 注入漏洞鼎游票务系统 /system/ImageViewServlet 文件读取漏洞科荣AIO管理系统 /ReportServlet getFileList 目录遍历漏洞Kyan 网络监控设备 /license.php 命令执行漏洞Fortra GoAnywhere MFT /goanywhere/license/Unlicensed.xhtml 权限绕过漏洞(CVE-2025-10035)用友U8 Cloud /servlet/~uap/nc.merp.bs.NCMERPServlet XML 外部实体注入漏洞