fortra has 5 CVEs on record between 2023 and 2026. 1 was published in the last 90 days. The median CVSS is 7.7 (high), with 2 rated critical. 40% have been exploited in the wild — well above the 1% corpus average, so fortra flaws are worth patching on sight. Most affected products: core_privileged_access_manager_server (2), goanywhere_managed_file_transfer (2), GoAnywhere MFT (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 40% vs 1% corpus
- Median CVSS
- 7.7
- Publish → KEV
- —(2)
- Last 90 days
- 1 prev 2
Products
- core_privileged_access_manager_server 2
- goanywhere_managed_file_transfer 2
- GoAnywhere MFT 1
Worst active — by depth score
CVE-2025-10035Critical· 10.0A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.100CVE-2023-0669High· 7.2Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object90CVE-2026-9862Critical· 9.8Fortra's Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service54CVE-2026-15913High· 7.7In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT allows Web Users with both Secure Folders and Secure Mail permissions to escape their sandboxed home directory, achi…42CVE-2026-9863High· 7.5Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations41
fortra vulnerabilities
CVEs affecting fortra, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2026-15913High· 7.7In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT allows Web Users with both Secure Folders and Secure Mail permissions to escape their sandboxed home directory, achi…
In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT allows Web Users with both Secure Folders and Secure Mail permissions to escape their sandboxed home directory, achi…
CVE-2026-9863High· 7.5Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations
Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations. A malicious or compromised legacy tar-installed client selected for upgrade or patching…
CVE-2026-9862Critical· 9.8Fortra's Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service
Fortra's Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the …
CVE-2025-10035Critical· 10.0CISA KEVPoCA deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.
A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.
CVE-2023-0669High· 7.2CISA KEVPoCFortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object
Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in versi…