logo

Fortra Discloses Critical Auth Bypass Vuln in GoAnywhere MFT

ID: 0d5acc2b-495f-5ff6-9fa3-6f30d9630c56

STIX ID: report--0d5acc2b-495f-5ff6-9fa3-6f30d9630c56

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-01-24

Date Updated: 2026-05-05

Author: Jai Vijayan, Contributing Writer

...
...

A critical authentication-bypass vulnerability (CVE-2024-0204) affecting Fortra GoAnywhere MFT was disclosed and a proof-of-concept exploit published by Horizon3.ai; the flaw allows unauthenticated attackers to create admin accounts, is trivial to scan for and exploit, and remains largely unpatched (Tenable telemetry shows <4% of assets updated), raising high risk of mass exploitation similar to prior Cl0p attacks on GoAnywhere.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.