Fortra GoAnywhere MFT
cpe:2.3:a:fortra:goanywhere_managed_file_transfer:*:*:*:*:*:*:*
This vulnerability is being actively exploited in the wild.
A deserialization vulnerability has been identified in the License Servlet of Fortra's GoAnywhere MFT. This vulnerability allows an actor with a validly forged license response signature to deserialize an arbitrary, actor-controlled object, which could potentially lead to command injection.
Exploitation of this vulnerability could result in arbitrary command execution on the server where GoAnywhere MFT is running.
Users are advised to upgrade to the latest patched version (7.8.4) or the Sustain Release 7.6.3. Additionally, access to the GoAnywhere Admin Console should not be open to the public, as exploitation is highly dependent on the system being externally exposed to the internet.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.