Brute Force Vulnerability in Fortra's GoAnywhere MFT SFTP Service
CVE-2025-14362

7.3HIGH

Key Information:

Vendor

Fortra

Vendor
CVE Published:
21 April 2026

What is CVE-2025-14362?

Fortra's GoAnywhere MFT prior to version 7.10.0 has a vulnerability in its SFTP service where the login limit is not enforced when users authenticate using SSH keys. This oversight allows attackers to potentially guess SSH keys through brute force methods, exposing sensitive systems to unauthorized access. Organizations using affected versions should evaluate their configurations and consider updating to mitigate this risk.

Affected Version(s)

GoAnywhere MFT 0 < 7.10.0

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.