News of yet another severe vulnerability affecting a managed file transfer product broke recently; the second in so many years to affect Fortra’s GoAnywhere software. Identified as CVE-2025-10035, NIST’s description says “a deserialization vulnerability in the License Servlet of Fortra’s GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.” The vulnerability was assigned a maximum critical score of 10.
If you are keeping score, the GoAnywhere vulnerability joins a long list since 2023 that also includes WingFTP, CrushFTP, MOVEit, Aspera, Accelion/Kiteworks, and Sharefile. Security researchers say that threat actors have been paying attention and are targeting managed file transfer because of the weaknesses that have been found and because of the role MFT software plays in accessing and moving highly sensitive corporate information.
Pay Attention to Security
That trend puts the onus on managed file transfer software vendors to pay attention to the products they offer, and to invest in innovations that improve security of the product and for the user. That has been our goal from the start here at Coviant Software, and it is why we recently announced the addition of threat intelligence to our Diplomat MFT family of secure managed file transfer products.
Threat intelligence means that Diplomat MFT (v9.4.1) correlates every attempt to connect to an SFTP server against a list of IP addresses and sources known to be high-risk, blocking them in real-time. We’ve also updated our administrative tools to provide corresponding IP administration access rules and and option to enforce the automatic deletion of non-encrypted files to minimize the risk of malicious payloads. When viewed in consideration with the extensive list of security features that have made Diplomat MFT a trusted part of the data security, management, and compliance programs of many organizations, these features build on our strong 20+ year record of security and reliability.
Threat Intelligence… Standard
Of note, threat intelligence is not offered as a value-added premium; it is a standard part of our secure architecture. That’s because we believe a managed file transfer solution should be secure-by-design, easy to use, and not cost a fortune. And it should be incumbent for an MFT vendor to protect their product before it is deployed, not charge extra for security after the fact. By making security easy and automatic, we minimize the risk of human error while maximizing the efficiency and simplicity of critical file transfers so that whether you are a large enterprise or a small business, you get the best protection available.
We are proud that Diplomat MFT boasts built-in compliance reporting tools to support compliance requirements for regulations like HIPAA and GDPR, test-mode to validate proper function of new MFT workflows before launch, and LDAP integration to ensure authentication and permissions are consistent with organizational policy. All that is in addition to longstanding usability and security features like:
- PGP encryption management;
- Post-Quantum computing cryptographic algorithms;
- Authorized recipient/destination confirmation;
- Scheduler with virtually unlimited concurrent job capacity;
- Process data capture for compliance audit reporting and troubleshooting; and,
- Notifications to communication channels of choice (email, text, Slack, Teams, etc.).
Seamless Security Operations
Diplomat MFT’s secure architecture and deployment in conjunction with the Diplomat MFT SFTP Server and Edge Gateway keeps files and connections secure before, during, and after transfer, allowing users to securely exchange files with unlimited B2B partners across a wide variety of endpoints, including cloud storage providers, traditional FTP servers, remote agents, even email. And the solution works seamlessly with business applications like ERP and CRM platforms, and cloud storage services like S3, Azure, SharePoint, Box, Dropbox, and more.
While we are disappointed to learn of yet another vulnerability affecting a product in our corner of the technology industry, Coviant Software is proud that Diplomat MFT has never been breached. We will continue to track security trends and invest in improvements to keep that track record intact. If you’re fed up with your current MFT software after another fire drill and want more information about what Coviant Software has to offer, get in touch. You’ll talk with an MFT expert and get honest answers. And if you decide to invest in Diplomat MFT, you’ll pay an honest price.
