CVE-2026-0972: Fortra GoAnywhere Managed File Transfer
Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.
HTML injection is possible in system generated emails in Fortra's GoAnywhere MFT prior to 7.10.0. Note: The title, details, and description of this CVE were corrected post-publishing.
Affected products
- Fortra GoAnywhere Managed File Transfer: before 7.10.0 (fixed in 7.10.0)
Published 2026-04-21. Last modified 2026-06-17.