CVE-2025-8148: Fortra GoAnywhere Managed File Transfer
Medium severity, CVSS 4.2. EPSS: 0.2% chance of exploitation in the next 30 days.
An Improper Access Control in the SFTP service in Fortra's GoAnywhere MFT prior to version 7.9.0 allows Web Users with an Authentication Alias and a valid SSH key but limited to Password authentication for SFTP to still login using their SSH key.
Affected products
- Fortra GoAnywhere Managed File Transfer: before 7.9.0 (fixed in 7.9.0)
Published 2025-12-05. Last modified 2026-09-25.