Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Goanywhere MFT — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in Goanywhere MFT, with AI-generated Chinese analysis, references, and POCs.

This page documents known security weaknesses associated with the Goanywhere MFT product from GoAnywhere, a leading managed file transfer solution. It aggregates a comprehensive list of vulnerabilities affecting this specific software, focusing on critical issues that have been publicly disclosed and analyzed. The collection covers advisory data and vulnerability records spanning from the initial release of the software up to recent updates, ensuring a broad historical perspective on the product's security posture. Users can discover detailed insights into how GoAnywhere MFT has handled security flaws over time, allowing them to track vendor advisories and understand the context behind each disclosure. This resource is designed to help security professionals, system administrators, and auditors understand a specific weakness class by examining its manifestations within the Goanywhere MFT environment. It serves as a central reference point for looking up the product’s vulnerability history, enabling stakeholders to assess risk exposure and prioritize remediation efforts effectively. By providing structured data on past incidents, this page supports informed decision-making regarding patch management and infrastructure security. It does not promote any specific vendor capabilities but rather presents factual records of identified defects, misconfigurations, and design flaws. The information herein is compiled from various public sources and vendor notifications, offering a transparent view of the security challenges faced by users of Goanywhere MFT. This aggregation aids in maintaining a clear understanding of the threat landscape surrounding managed file transfer solutions.

Vendor: Fortra

CVE IDTitleCVSSSeverityPublished
CVE-2026-1089 User‑Controlled HTTP Header In Fortra's GoAnywhere MFT Allows Arbitrary DNS Lookups CWE-74 6.5 Medium2026-04-21
CVE-2026-0972 HTML Injection possible in system generated emails in Fortra's GoAnywhere MFT CWE-74 5.4 Medium2026-04-21
CVE-2026-0971 GoAnywhere MFT SAML Sessions do not redirect to logout URL on session timeout CWE-613 4.3 Medium2026-04-21
CVE-2025-14362 GoAnywhere MFT SFTP Service Login Vulnerable to Brute Force Attack Under Certain Circumstances CWE-307 7.3 High2026-04-21
CVE-2025-1241 Encryption vulnerable to brute-force decryption in GoAnywhere MFT CWE-326 5.8 Medium2026-04-21
CVE-2025-8148 CVE-2025-8148 Improper Access Control in SFTP service of GoAnywhere MFT CWE-732 4.2 Medium2025-12-05
CVE-2025-10035 Deserialization Vulnerability in GoAnywhere MFT's License Servlet CWE-77 10.0 Critical2025-09-18
CVE-2025-3871 Broken Access Control Leads to Limited Denial of Service in GoAnywhere MFT 7.8.0 and earlier CWE-862 5.3 Medium2025-07-16
CVE-2024-11922 Input Validation vulnerability in Web Client emails that do not go through Secure Mail CWE-79 6.3 Medium2025-04-28
CVE-2024-9945 Limited Information Disclosure in GoAnywhere MFT Prior to 7.7.0 CWE-200 5.3 Medium2024-12-13
CVE-2024-25157 Authentication bypass in GoAnywhere MFT prior to 7.6.0 CWE-303 6.5 Medium2024-08-14
CVE-2024-25156 Path traversal in GoAnywhere MFT 7.4.1 and Earlier CWE-22 6.5 Medium2024-03-14
CVE-2024-0204 Authentication Bypass in GoAnywhere MFT CWE-425 9.8 Critical2024-01-22
CVE-2023-0669 Fortra GoAnywhere MFT License Response Servlet Command Injection CWE-502 8.8 -2023-02-06

All 14 known CVE vulnerabilities affecting Goanywhere MFT with full Chinese analysis, references, and POCs where available.