Fortra GoAnywhere MFT SFTP Brute Force Vulnerability for SSH Key Authentication

Vulnerability

A vulnerability exists in Fortra's GoAnywhere MFT SFTP service in versions prior to 7.10.0. The issue arises because the login limit is not enforced for users authenticated with SSH keys, allowing for brute force attacks to guess the SSH keys.

Impact

Exploitation of this vulnerability could lead to successful brute force attacks on SSH keys, potentially allowing unauthorized access via SFTP.

Remediation

Users can upgrade to Fortra GoAnywhere MFT version 7.10.0 or later to address this vulnerability.

Added: Apr 21, 2026, 3:40 PM
Updated: Apr 21, 2026, 3:40 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
0.6
exploitability
7.6
remediation
0.0
relevance
6.4
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.