CVE-2024-0204: Fortra GoAnywhere Managed File Transfer

Critical severity, CVSS 9.8. EPSS: 95.1% chance of exploitation in the next 30 days.

Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal.

Affected products

  • Fortra GoAnywhere Managed File Transfer: from 7.0.0, before 7.4.1 (fixed in 7.4.1); version 6.0.0 only

Published 2024-01-22. Last modified 2026-06-17.