Posted inCloudflare WAF
WAF – WAF Release – 2025-09-28 – Emergency
This week highlights a critical vendor-specific vulnerability: a deserialization flaw in the License Servlet of Fortra’s GoAnywhere MFT. By forging a license response signature, an attacker can trigger deserialization of arbitrary objects, potentially leading to command injection. Key Findings Cisco…