logo

Months after first GoAnywhere MFT zero-day attacks, Censys still sees ~180 public admin panels

ID: 3b187ec2-4dad-5b23-bce9-f8a3674cacb4

STIX ID: report--3b187ec2-4dad-5b23-bce9-f8a3674cacb4

Feed Name: Censys Blog

Threat Score
85/100

Date Published: 2023-05-01

Date Updated: 2026-04-27

Author: Ivonne Francia; Himaja Motheram

...
...

**Executive Summary:** In early February 2023 a critical pre-authentication RCE (CVE-2023-0669) in Fortra's GoAnywhere MFT was actively exploited by ransomware groups (notably Clop and BlackCat) to exfiltrate data from multiple high-profile organizations; Censys observed 179 exposed admin panels as of April 25, 2023 with 55 instances likely unpatched, and recommends upgrading to GoAnywhere 7.1.2+, rotating master encryption keys, resetting credentials, reviewing logs, and removing internet exposure of admin consoles.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.