PT-2026-33978 · Fortra · Goanywhere Mft

Published

2026-04-21

·

Updated

2026-04-21

·

CVE-2026-0972

CVSS v3.1

7.3

High

AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The login limit is not enforced on the SFTP service of Fortra's GoAnywhere MFT prior to 7.10.0 if the Web User attempting to be logged in to is configured to log in with an SSH Key, making the SSH key vulnerable to being guessed via Brute Force.

Fix

Improper Restriction of Excessive Authentication Attempts

Weakness Enumeration

Related Identifiers

CVE-2026-0972

Affected Products

Goanywhere Mft