A critical vulnerability with a CVSS score of 10.0 has been discovered in Fortra's GoAnywhere MFT software, widely used by enterprises for managed file transfer. This flaw allows unauthenticated remote code execution (RCE), posing a severe risk to organizations relying on this platform for secure data exchange. The vulnerability stems from improper input validation, enabling attackers to execute arbitrary commands on affected systems without needing credentials. Given the criticality, Fortra has issued an urgent security advisory and released patches to mitigate the threat. Enterprises are strongly advised to apply these updates immediately to prevent exploitation by threat actors. The flaw's severity and ease of exploitation make it a prime target for cybercriminals aiming to infiltrate corporate networks, steal sensitive data, or deploy ransomware. This incident underscores the importance of timely patch management and continuous monitoring of critical infrastructure software. Security teams should also consider implementing additional network-level protections and conduct thorough audits to detect any signs of compromise. Staying informed about such high-severity vulnerabilities is crucial for maintaining robust cybersecurity defenses in today's threat landscape.
This Cyber News was published on thehackernews.com. Publication date: Sun, 28 Sep 2025 23:29:04 +0000