CVE-2026-15913: Fortra GoAnywhere MFT
High severity, CVSS 7.7. EPSS: 0.4% chance of exploitation in the next 30 days.
In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT allows Web Users with both Secure Folders and Secure Mail permissions to escape their sandboxed home directory, achieving arbitrary file read.
Affected products
- Fortra GoAnywhere MFT: before 7.10.2 (fixed in 7.10.2)
Published 2026-09-09. Last modified 2026-09-10.