CVE-2024-25156: Fortra GoAnywhere Managed File Transfer

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

A path traversal vulnerability exists in GoAnywhere MFT prior to 7.4.2 which allows attackers to circumvent endpoint-specific permission checks in the GoAnywhere Admin and Web Clients.

Affected products

  • Fortra GoAnywhere Managed File Transfer: before 7.4.2 (fixed in 7.4.2)

Published 2024-03-14. Last modified 2026-06-17.