CVE-2025-8450: Fortra Filecatalyst
High severity, CVSS 8.2. EPSS: 0.3% chance of exploitation in the next 30 days.
Improper Access Control issue in the Workflow component of Fortra's FileCatalyst allows unauthenticated users to upload arbitrary files via the order forms page.
Affected products
- Fortra Filecatalyst: from 5.1.6, up to and including 5.2.0 Build 80
Published 2025-08-19. Last modified 2026-06-17.