← Vulnerability feed

Vulnerability record · CVE-2023-0669 · published 6 February 2023

CVE-2023-0669: Fortra GoAnywhere MFT pre-auth deserialization command injection

Fortra · Goanywhere Managed File Transfer

Fortra GoAnywhere MFT deserializes an attacker-controlled object in the License Response Servlet, allowing command injection before authentication. The flaw was patched in version 7.1.2. Because it is remotely reachable and was exploited as a zero-day, it is a serious risk to internet-facing MFT deployments.

7.2 CVSS 3.1 High CISA KEV since 10 Feb 2023 Known ransomware use EPSS 100% · top 0.1% CWE-502 · Deserialization of untrusted data
7.2CVSS 3.1 base score
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
17References, 6 tagged exploit
6 Aug 2026Last modified by NVD

Description

Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in version 7.1.2.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityPre-authentication remote code execution in an internet-facing file transfer product, listed in CISA KEV with known ransomware use and near-maximum EPSS.

What it is

Fortra GoAnywhere MFT deserializes an attacker-controlled object in the License Response Servlet, allowing command injection before authentication. The flaw was patched in version 7.1.2. Because it is remotely reachable and was exploited as a zero-day, it is a serious risk to internet-facing MFT deployments.

Impact

An attacker can execute arbitrary commands on the GoAnywhere MFT server, leading to full compromise of the host and any data it manages. CISA KEV notes known ransomware campaign use, and cl0p is documented as using it.

Attack surface

Reached over the network via the License Response Servlet; the description calls it pre-authentication, though the CVSS vector lists PR:H, so the record is inconsistent on required privileges. No user interaction is indicated.

Exploitation

Actively exploited: it is in CISA KEV with a 2023-03-03 due date and known ransomware use, EPSS 30-day probability is 0.99999, and multiple references are tagged Exploit.

What to do

  • Upgrade GoAnywhere MFT to version 7.1.2 or later immediately.
  • If patching cannot be done at once, restrict network access to the administrative and License Response interfaces to trusted sources.
  • Monitor for and block exploitation attempts against the License Response Servlet.
  • Review the vendor advisory and Rapid7 mitigation guidance for interim controls.
  • After patching, hunt for signs of prior compromise given known ransomware use.

Detection

  • Inspect web/proxy logs for requests to the GoAnywhere License Response Servlet, especially unusual or malformed payloads.
  • Monitor for unexpected child processes spawned by the GoAnywhere MFT service or Java process.
  • Look for outbound connections or file writes from the GoAnywhere host that do not match normal MFT behavior.
  • Correlate with CISA KEV and known cl0p ransomware indicators for post-exploitation activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-0669 to the Known Exploited Vulnerabilities catalog on 10 February 2023 as "Fortra GoAnywhere MFT Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 3 March 2023.

Ransomware crews whose documented playbooks reference this CVE: