Encrypted values in Fortra's GoAnywhere MFT prior to version 7.10.0 and GoAnywhere Agents prior to version 2.2.0 utilize a static IV which allows admin users to brute-force decryption of data.
References
| Link | Resource |
|---|---|
| https://fortra.com/security/advisories/product-security/FI-2026-001 | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
23 Apr 2026, 14:12
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Microsoft
Fortra goanywhere Agents Linux linux Kernel Linux Fortra goanywhere Managed File Transfer Microsoft windows Apple macos Apple Fortra |
|
| CPE | cpe:2.3:a:fortra:goanywhere_managed_file_transfer:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* cpe:2.3:a:fortra:goanywhere_agents:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:* |
|
| References | () https://fortra.com/security/advisories/product-security/FI-2026-001 - Vendor Advisory |
21 Apr 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-21 15:16
Updated : 2026-04-23 14:12
NVD link : CVE-2025-1241
Mitre link : CVE-2025-1241
CVE.ORG link : CVE-2025-1241
JSON object : View
Products Affected
fortra
- goanywhere_agents
- goanywhere_managed_file_transfer
microsoft
- windows
linux
- linux_kernel
apple
- macos
CWE
CWE-326
Inadequate Encryption Strength
