VulnSea

fortra has 5 CVEs on record between 2023 and 2026. 1 was published in the last 90 days. The median CVSS is 7.7 (high), with 2 rated critical. 40% have been exploited in the wild — well above the 1% corpus average, so fortra flaws are worth patching on sight. Most affected products: core_privileged_access_manager_server (2), goanywhere_managed_file_transfer (2), GoAnywhere MFT (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
40% vs 1% corpus
Median CVSS
7.7
Publish → KEV
(2)
Last 90 days
1 prev 2

Products

  • core_privileged_access_manager_server 2
  • goanywhere_managed_file_transfer 2
  • GoAnywhere MFT 1
5
Total CVEs
2
Critical
2
CISA KEV
2
Exploited

fortra vulnerabilities

CVEs affecting fortra, newest first. Open any entry for full detail, references, and exploit status.

5 CVEsRSS

CVE-2026-15913High· 7.7
1w ago

In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT allows Web Users with both Secure Folders and Secure Mail permissions to escape their sandboxed home directory, achi…

In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT allows Web Users with both Secure Folders and Secure Mail permissions to escape their sandboxed home directory, achi…

TwilightFortra · GoAnywhere MFTEPSS 0.39%via NVD
CVE-2026-9863High· 7.5
3mo ago

Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations

Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations. A malicious or compromised legacy tar-installed client selected for upgrade or patching…

Twilightfortra · core_privileged_access_manager_serverEPSS 0.60%via NVD
CVE-2026-9862Critical· 9.8
3mo ago

Fortra's  Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service

Fortra's  Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the …

Midnightfortra · core_privileged_access_manager_serverEPSS 0.99%via NVD
CVE-2025-10035Critical· 10.0CISA KEVPoC
1y ago

A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.

A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.

Hadalfortra · goanywhere_managed_file_transferEPSS 100%via NVD
CVE-2023-0669High· 7.2CISA KEVPoC
3y ago

Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object

Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in versi…

Abyssalfortra · goanywhere_managed_file_transferEPSS 100%via NVD
fortra vulnerabilities (CVEs) · VulnSea