logo

Patch Your GoAnywhere MFT Immediately - Critical Flaw Lets Anyone Be Admin

ID: 758244e0-0927-567c-bd1f-c2e34455924b

STIX ID: report--758244e0-0927-567c-bd1f-c2e34455924b

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2024-01-24

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

A critical authentication-bypass vulnerability (CVE-2024-0204, CVSS 9.8) in Fortra's GoAnywhere MFT allows attackers to create admin accounts via a path traversal in /InitialAccountSetup.xhtml; a PoC was published, roughly 96.4% of deployments were reported vulnerable as of Jan 23, 2024, and Fortra released fixes (7.4.1) and temporary workarounds.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.