Beware Cybercriminals Taking Advantage of Unpatched Vulnerability in Fortras GoAnywhere MFT

A recently discovered security flaw in Fortras GoAnywhere MFT managed file transfer application is being actively exploited in the wild. The vulnerability was first reported by security reporter Brian Krebs on Mastodon. It is a type of remote code injection that requires access to the administrative console of the application, so it is important that the systems are not exposed to the public internet. According to security researcher Kevin Beaumont, there are over 1,000 on-premise instances that are publicly accessible, mostly in the U.S. Fortra's advisory suggests that customers should review all administrative users and watch for any unrecognized usernames, especially those created by the system. This implies that Fortra is likely seeing follow-up attacks that involve the creation of new administrative or other users to take control of or maintain access to vulnerable target systems. The cybersecurity company said it is possible for malicious actors to exploit reused, weak, or default credentials to gain administrative access to the console. Unfortunately, there is no patch available for the zero-day vulnerability yet, although Fortra has released workarounds to remove the License Response Servlet configuration from the web. Vulnerabilities in file transfer solutions have become attractive targets for attackers, with flaws in Accellion and FileZen being used for data theft and extortion.

This Cyber News was published on thehackernews.com. Publication date: Sat, 04 Feb 2023 05:54:02 +0000


Cyber News related to Beware Cybercriminals Taking Advantage of Unpatched Vulnerability in Fortras GoAnywhere MFT

Exploit released for Fortra GoAnywhere MFT auth bypass bug - Exploit code is now available for a critical authentication bypass vulnerability in Fortra's GoAnywhere MFT software that allows attackers to create new admin users on unpatched instances via the administration portal. GoAnywhere MFT is a web-based ...
1 year ago Bleepingcomputer.com CVE-2024-0204
Fortra's GoAnywhere MFT Software Faces Exploitation, No Evidence of Active Exploitation Detected - Reports on the exploitation of Fortra's GoAnywhere MFT file transfer software raised concerns due to the potential development of exploit code from a publicly released Proof of Concept. As of Thursday afternoon, there was no evidence of active ...
1 year ago Cysecurity.news CVE-2024-0204 LockBit
Beware Cybercriminals Taking Advantage of Unpatched Vulnerability in Fortras GoAnywhere MFT - A recently discovered security flaw in Fortras GoAnywhere MFT managed file transfer application is being actively exploited in the wild. The vulnerability was first reported by security reporter Brian Krebs on Mastodon. It is a type of remote code ...
2 years ago Thehackernews.com
Revealing a Way to Take Advantage of a Newly Discovered Security Flaw in GoAnywhere MFT - A security researcher has released proof-of-concept exploit code that can be used to perform unauthenticated remote code execution on vulnerable GoAnywhere MFT servers. GoAnywhere MFT is a web-based and managed file transfer tool designed to help ...
2 years ago Bleepingcomputer.com
Revealing a Vulnerability in GoAnywhere MFT that is Currently Being Abused - A security vulnerability in GoAnywhere MFT, a web-based and managed file transfer tool, has been actively exploited. The exploit code was released by Florian Hauser of Code White, which allows for unauthenticated remote code execution on vulnerable ...
2 years ago Bleepingcomputer.com
Emergency Fix Released for GoAnywhere MFT ZeroDay Vulnerability Being Exploited - Fortra has released an emergency patch to address a security flaw in its GoAnywhere MFT secure file transfer tool that is being actively exploited by attackers. The vulnerability allows them to gain remote code execution on vulnerable GoAnywhere MFT ...
2 years ago Bleepingcomputer.com
Maximum severity GoAnywhere MFT flaw exploited as zero-day - A critical zero-day vulnerability in the GoAnywhere Managed File Transfer (MFT) software is currently being exploited in the wild, posing a significant security risk to organizations using this platform. The flaw, rated with maximum severity, allows ...
2 months ago Bleepingcomputer.com CVE-2023-34362
Fortra Releases Critical Patch for CVSS 10.0 Vulnerability in GoAnywhere MFT - Fortra has released a critical security patch addressing a CVSS 10.0 vulnerability in its GoAnywhere Managed File Transfer (MFT) software. This vulnerability poses a severe risk as it allows remote code execution, potentially enabling attackers to ...
2 months ago Thehackernews.com CVE-2025-12345
Microsoft warns of critical GoAnywhere bug exploited in ransomware attacks - Microsoft has issued a critical security warning regarding a vulnerability in the GoAnywhere managed file transfer (MFT) software, which is actively being exploited by ransomware attackers. The flaw, identified as CVE-2023-0669, allows threat actors ...
1 month ago Bleepingcomputer.com CVE-2023-0669
GoAnywhere 0-day RCE exploited by MedusaLocker ransomware gang - A critical zero-day remote code execution (RCE) vulnerability in the GoAnywhere Managed File Transfer (MFT) software has been actively exploited by the MedusaLocker ransomware group. This vulnerability allows attackers to execute arbitrary code on ...
1 month ago Cybersecuritynews.com CVE-2023-0669 MedusaLocker
A Fix Released to Stop the Unauthorized Use of GoAnywhere MFT Software - Recently, a zero-day vulnerability was discovered in the GoAnywhere managed file transfer software, and news of active exploitation has been reported. Fortra, formerly known as HelpSystems, released two security notifications with mitigations and ...
2 years ago Securityweek.com
Hackers Can Gain Access to Servers Through a GoAnywhere MFT Security Flaw - GoAnywhere MFT, a secure web file transfer solution, has warned customers of a zero-day remote code execution vulnerability on exposed administrator consoles. This exploit requires access to the administrative console, which should not normally be ...
2 years ago Bleepingcomputer.com
10 of the biggest zero-day attacks of 2023 - Here are 10 of the biggest zero-day attacks of 2023 in chronological order. Zero-day attacks started strong in 2023 with CVE-2023-0669, a pre-authentication command injection vulnerability in Fortra's GoAnywhere managed file transfer product. ...
1 year ago Techtarget.com CVE-2023-0669 CVE-2023-34362 CVE-2023-36884 CVE-2023-4863 CVE-2023-41992 CVE-2023-41991 CVE-2023-41993 CVE-2023-22515
GoAnywhere MFT Platform Vulnerability: Critical Flaw Exposes Data to Attackers - A critical vulnerability has been discovered in the GoAnywhere Managed File Transfer (MFT) platform, widely used by enterprises for secure file transfers. This flaw allows attackers to potentially execute unauthorized commands and access sensitive ...
2 months ago Cybersecuritynews.com CVE-2023-3519
Fortra warns of max-severity flaw in GoAnywhere MFT's License Servlet - Fortra has issued a critical security warning regarding a maximum severity vulnerability found in the License Servlet component of its GoAnywhere Managed File Transfer (MFT) software. This flaw poses a significant risk as it could allow unauthorized ...
2 months ago Bleepingcomputer.com CVE-2024-28199
Fortra GoAnywhere 0-Day Vulnerability Exploited in the Wild - A critical zero-day vulnerability has been discovered in Fortra's GoAnywhere MFT (Managed File Transfer) software, actively exploited by threat actors. This flaw allows unauthenticated attackers to execute arbitrary code remotely, posing significant ...
2 months ago Cybersecuritynews.com CVE-2023-34362
Microsoft issues critical patch for GoAnywhere zero-day exploited in attacks - Microsoft has released a critical security update addressing a zero-day vulnerability in the GoAnywhere MFT (Managed File Transfer) software, which has been actively exploited by threat actors. The vulnerability allows attackers to execute arbitrary ...
1 month ago Infosecurity-magazine.com CVE-2023-34362
CVE-2022-49763 - In the Linux kernel, the following vulnerability has been resolved: ...
6 months ago
Week in review: 15 million Trello users' scraped data on sale, attackers can steal NTLM hashes - The reality of hacking threats in connected car systemsIn this Help Net Security interview, Ivan Reedman, Director of Secure Engineering at IOActive, discusses how manufacturers, government regulations, and consumers are adapting to these new ...
1 year ago Helpnetsecurity.com Cozy Bear
Medusa ransomware exploit targets Fortra GoAnywhere flaw - A new ransomware strain named Medusa is actively exploiting a critical vulnerability in Fortra's GoAnywhere managed file transfer software. This flaw allows attackers to execute arbitrary code remotely, leading to potential ransomware deployment and ...
1 month ago Darkreading.com CVE-2023-0669
Alert for GoAnywhere MFT Users Potential ZeroDay Vulnerability Detected - Users of the GoAnywhere secure managed file transfer software have been warned about a potential security risk. This software, created by Fortra (formerly known as HelpSystems), is designed to help organizations securely exchange data with their ...
2 years ago Securityweek.com
PoC exploit for critical Fortra FileCatalyst MFT vulnerability released - Proof-of-concept exploit code for a critical RCE vulnerability in Fortra FileCatalyst MFT solution has been published. Fortra FileCatalyst is an enterprise managed file transfer software solution that includes several components: FileCatalyst Direct, ...
1 year ago Helpnetsecurity.com CVE-2024-25153
CVE-2025-40068 - In the Linux kernel, the following vulnerability has been resolved: ...
1 month ago
Cybersecurity Tips to Stay Safe this Holiday Season - Cybercriminals take advantage of this hectic time to target holiday shoppers and travelers. Their goal is to catch you off guard when or where you least expect it. If you're like me you might be doing some last-minute shopping and looking for the ...
1 year ago Cybersecurity-insiders.com
The Evolving Cybersecurity Landscape in 2024: Predictions and Preparations - As we prepare to ring in the new year, the ever-evolving cybersecurity landscape promises to bring new cyber threat actors, vulnerabilities, and weaknesses to counter. As technology evolves, so do cyber threat actors' tactics, techniques, and ...
1 year ago Securityboulevard.com