ZeroHour
Product

GoAnywhere MFT

1 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

Fortra security advisory (AV26-906)

Canada's Cyber Centre advises that Fortra GoAnywhere MFT Endpoint versions prior to 7.10.2 are affected by a path traversal vulnerability.

The Canadian Centre for Cyber Security issued advisory AV26-906 noting that Fortra GoAnywhere MFT Endpoint versions prior to 7.10.2 are affected by a path traversal vulnerability. The advisory was published September 10, 2026, referencing Fortra's own security advisory. No exploitation details or CVE id are provided; administrators are urged to review the links and apply the 7.10.2 update.

Canadian Centre for Cyber Security · 5d agoAdvisory

Supply Chain Attacks in 2026: Why Threat Intelligence Is the Only Early Warning System That Works

Cyble argues supply chain attacks are a primary breach vector, citing Verizon DBIR third-party figures and CISA SBOM guidance to pitch its TPRM platform.

Cyble's vendor blog frames third-party compromise as a first-order breach risk, citing Verizon's 2026 DBIR finding that third parties were involved in 48% of breaches, up 60% year over year. It recounts the Cl0p campaigns against Progress MOVEit Transfer (CVE-2023-34362), which affected over 2,700 organizations and 93 million people, and Fortra GoAnywhere (CVE-2023-0669) with roughly 130 claimed victims. It also highlights CISA and NSA's 2026 Minimum Elements for a Software Bill of Materials covering open-source, AI, and SaaS components. The piece concludes by promoting Cyble's Third-Party Risk Management platform.

Cyble · 12d agoIndustryCVE-2023-34362CVE-2023-0669

Related CVEs

  • Unauthenticated SQL Injection in Progress MOVEit Transfer
    CVE-2023-34362 is an unauthenticated SQL injection flaw (CWE-89) in Progress MOVEit Transfer that allows an attacker with no credentials to gain unauthorized access to the product's database. It is triggered remotely via crafted input submitted to the MOVEit Transfer web application, with the impact varying by the backend database engine in use (MySQL, Microsoft SQL Server, or Azure SQL). A successful attacker can infer the structure and contents of the database and, depending on the engine, execute SQL statements that alter or delete database elements, exposing data handled by the file-transfer service. Any organization running an internet-reachable MOVEit Transfer instance is affected; public internet-exposure scans around disclosure identified on the order of a few thousand servers, each typically serving enterprise or government user bases. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2023-06-02 with known ransomware use and an EPSS exploitation probability of 99.9% (100th percentile), while no public PoC is known.
    · Progress MOVEit Transfer KEV ransomware PoC large
  • Pre-Authentication Deserialization RCE in Fortra GoAnywhere MFT
    Fortra (formerly HelpSystems) GoAnywhere MFT is vulnerable to pre-authentication remote code execution (CWE-502) in the License Response Servlet, which deserializes an attacker-controlled object without validating it. An unauthenticated attacker who can reach the exposed administrative interface can send a crafted serialized object to the servlet and trigger code execution on the server. Successful exploitation gives the attacker the ability to run arbitrary code in the context of the application, which has been leveraged for ransomware operations. All organizations running GoAnywhere MFT with the affected component reachable by untrusted networks are in scope. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-02-10, ransomware use is confirmed, and EPSS puts the 30-day exploitation probability at 100%.
    · Fortra GoAnywhere MFT KEV ransomware PoC ×3moderate

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.