logo

Hackers Ready to Go Anywhere with Critical Vulnerability in GoAnywhere MFT (CVE-2024-0204) | UpGuard

ID: d428fe4c-5309-50b9-8bb8-3f03324f72e4

STIX ID: report--d428fe4c-5309-50b9-8bb8-3f03324f72e4

Feed Name: UpGuard Blog

Threat Score
75/100

Date Published: 2024-01-24

Date Updated: 2026-05-01

...
...

CVE-2024-0204 is a critical authentication-bypass vulnerability in Fortra GoAnywhere MFT (affecting versions before 7.4.1) that can let unauthenticated actors create admin users and gain broad privileged access; Fortra released a patch (7.4.1) and mitigations in December 2023/January 2024, Horizon3.ai published a PoC, and the advisory recommends immediate upgrading, log review for IOCs (new admin accounts, access to admin creation endpoints, log entries), and following incident-response procedures if suspicious activity is found.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.