Fortra Security Update – 22 April 2026

Fortra has released a security update to fix several vulnerabilities across Fortra’s GoAnywhere MFT versions before 7.10.0.

The addressed vulnerabilities could allow the remote attacker to hijack SAML sessions, perform network reconnaissance and DNS rebinding, obtain sensitive information, and gain access to the affected systems.

Sample of the addressed vulnerabilities:

GoAnywhere MFT SFTP Service Login Brute Force Vulnerability (CVE-2026-0972):

  • CVSS: 7.3
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Access
Vulnerabilities
  • CVE-2026-0972
  • CVE-2026-0971
  • CVE-2026-1089
  • CVE-2025-14362
  • CVE-2025-1241
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Fortra Security Advisory

References