logo

GoAnywhere MFT vulnerabilities are Going Nowhere for Now

ID: 67a90788-c056-57e5-abd9-6be5014b715d

STIX ID: report--67a90788-c056-57e5-abd9-6be5014b715d

Feed Name: Censys Blog

Threat Score
75/100

Date Published: 2024-01-25

Date Updated: 2026-04-27

Author: Ivonne Francia; Himaja Motheram

...
...

A public proof-of-concept was released for CVE-2024-0204, a critical authentication-bypass in Fortra GoAnywhere MFT that allows unauthenticated attackers to create admin accounts via the administrative console; Censys found nearly 170 admin interfaces exposed on the public internet, and the report urges immediate updating to GoAnywhere 7.4.1 (or applying vendor workarounds), checking for added admin users and login activity, and avoiding public exposure of admin panels.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.