← Vulnerability feed

Vulnerability record · CVE-2025-14362 · published 21 April 2026

CVE-2025-14362: Fortra goanywhere managed file transfer improper restriction of authentication attempts vulnerability

Fortra · Goanywhere Managed File Transfer

The login limit is not enforced on the SFTP service of Fortra's GoAnywhere MFT prior to 7.10.0 if the Web User attempting to be logged in to is configured to log in with an SSH Key, making the SSH key vulnerable to being guessed via Brute Force.

7.3 CVSS 3.1 High EPSS 0.19% · top 91.9% CWE-307 · Improper restriction of authentication attempts
7.3CVSS 3.1 base score
0.19%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

The login limit is not enforced on the SFTP service of Fortra's GoAnywhere MFT prior to 7.10.0 if the Web User attempting to be logged in to is configured to log in with an SSH Key, making the SSH key vulnerable to being guessed via Brute Force.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-14362 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-10035Fortra GoAnywhere MFT License Servlet deserialization to command injectionThe License Servlet in Fortra GoAnywhere MFT deserializes untrusted data, and an attacker who can present a validly forged license response signature…KEVEPSS 100%analysed7.2CVE-2023-0669Fortra GoAnywhere MFT pre-auth deserialization command injectionFortra GoAnywhere MFT deserializes an attacker-controlled object in the License Response Servlet, allowing command injection before authentication. T…KEVEPSS 100%analysed9.8CVE-2024-0204Fortra GoAnywhere MFT authentication bypass in admin portalGoAnywhere MFT before 7.4.1 contains an authentication bypass (CWE-425, forced browsing) in the administration portal that lets an unauthenticated us…EPSS 95%analysed6.5CVE-2026-1089Fortra goanywhere managed file transfer injection vulnerabilityUser‑Controlled HTTP Header in Fortra's GoAnywhere MFT prior to version 7.10.0 allows attackers to trigger a DNS lookup, as well as DNS Rebinding and…EPSS 0.23%6.5CVE-2024-25157Fortra goanywhere managed file transfer improper authentication vulnerabilityAn authentication bypass vulnerability in GoAnywhere MFT prior to 7.6.0 allows Admin Users with access to the Agent Console to circumvent some permis…EPSS 0.50%6.5CVE-2024-25156Fortra goanywhere managed file transfer path traversal vulnerabilityA path traversal vulnerability exists in GoAnywhere MFT prior to 7.4.2 which allows attackers to circumvent endpoint-specific permission checks in th…EPSS 0.39%5.4CVE-2026-0972Fortra goanywhere managed file transfer injection vulnerabilityHTML injection is possible in system generated emails in Fortra's GoAnywhere MFT prior to 7.10.0. Note: The title, details, and description of this C…EPSS 0.16%5.4CVE-2024-11922Fortra goanywhere managed file transfer cross-site scripting vulnerabilityMissing input validation in certain features of the Web Client of Fortra's GoAnywhere prior to version 7.8.0 allows an attacker with permission to tr…EPSS 0.23%

Source: NIST National Vulnerability Database (record CVE-2025-14362), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.