A critical zero-day vulnerability has been discovered in Fortra's GoAnywhere MFT (Managed File Transfer) software, actively exploited by threat actors. This flaw allows unauthenticated attackers to execute arbitrary code remotely, posing significant risks to organizations relying on this platform for secure file transfers. The vulnerability, tracked as CVE-2023-34362, affects multiple versions of GoAnywhere and has prompted urgent security advisories from Fortra. Attackers exploit this weakness to gain unauthorized access, potentially leading to data breaches and ransomware attacks. Security experts urge immediate patching and mitigation measures to protect sensitive data and maintain operational integrity. This article delves into the technical details of the vulnerability, the exploitation methods observed in the wild, and best practices for defense. It also highlights the importance of timely updates and vigilant monitoring to thwart ongoing attacks leveraging this zero-day flaw. Organizations using GoAnywhere should prioritize incident response readiness and apply vendor patches without delay to mitigate risks associated with this critical security issue.
This Cyber News was published on cybersecuritynews.com. Publication date: Fri, 26 Sep 2025 13:15:17 +0000