Vulnerability Intelligence Report
GoAnywhere MFT SFTP Service Login Vulnerable to Brute Force Attack Under Certain Circumstances
CVE-2025-14362
The login limit is not enforced on the SFTP service of Fortra's GoAnywhere MFT prior to 7.10.0 if the Web User attempting to be logged in to is configured to log in with an SSH Key, making the SSH key vulnerable to being guessed via Brute Force.
No Active Exploit Signals
CVSS Base Score
7.3
HIGH
Exploitability:3.9
Impact Score:3.4
EPSS Probability:0.19%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-307 ↗CWE-307 Improper restriction of excessive authentication attempts
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Fortra | GoAnywhere MFT | 0 < 7.10.0 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.194%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Fortra, LLC · Vendor · USA |
| Reserved | 2025-12-09T17:26:54 |
| Published | 2026-04-21T14:14:08 |
| Last Updated | 2026-04-21T19:33:35 |
Community Chatter & Buzz