CVE-2026-0972: Fortra GoAnywhere Managed File Transfer

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

HTML injection is possible in system generated emails in Fortra's GoAnywhere MFT prior to 7.10.0. Note: The title, details, and description of this CVE were corrected post-publishing.

Affected products

  • Fortra GoAnywhere Managed File Transfer: before 7.10.0 (fixed in 7.10.0)

Published 2026-04-21. Last modified 2026-06-17.