Brute Force Vulnerability in Fortra's GoAnywhere MFT SFTP Service
CVE-2026-0972

7.3HIGH

Key Information:

Vendor

Fortra

Vendor
CVE Published:
21 April 2026

What is CVE-2026-0972?

Fortra's GoAnywhere MFT versions prior to 7.10.0 exhibit a vulnerability in the SFTP service where the login limit is not enforced for users utilizing SSH Key authentication. This flaw makes SSH Keys susceptible to brute force attempts, potentially allowing unauthorized access. Organizations using affected versions should implement immediate security measures to mitigate the risk associated with this vulnerability.

Affected Version(s)

GoAnywhere MFT 0 < 7.10.0

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.