logo

Fortra warns of new critical GoAnywhere MFT auth bypass, patch now

ID: 34341322-3c1e-5175-8107-45305007df7d

STIX ID: report--34341322-3c1e-5175-8107-45305007df7d

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-01-23

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Fortra disclosed a critical authentication-bypass in GoAnywhere MFT (CVE-2024-0204, CVSS 9.8) affecting versions prior to 7.4.1 that allows creation of admin accounts; a patch (7.4.1) and manual mitigations are available. The report warns PoC exploits may appear and recalls Clop's 2023 exploitation of a separate GoAnywhere zero-day that caused widespread data theft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.