Brute Force Vulnerability in Fortra's GoAnywhere MFT SFTP Service
CVE-2026-0972

5.4MEDIUM

Key Information:

Vendor

Fortra

Vendor
CVE Published:
21 April 2026

What is CVE-2026-0972?

Fortra's GoAnywhere MFT versions prior to 7.10.0 exhibit a vulnerability in the SFTP service where the login limit is not enforced for users utilizing SSH Key authentication. This flaw makes SSH Keys susceptible to brute force attempts, potentially allowing unauthorized access. Organizations using affected versions should implement immediate security measures to mitigate the risk associated with this vulnerability.

Affected Version(s)

GoAnywhere MFT 0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.