Vulnerabilities Fortra GoAnywhere MFT Zero-Day Exploited in Ransomware Attacks The Medusa ransomware operators exploited the GoAnywhere MFT vulnerability one week before patches were released. Ionut ArghireOctober 7, 2025
Vulnerabilities Recent Fortra GoAnywhere MFT Vulnerability Exploited as Zero-Day Eight days before patches, a threat actor exploited CVE-2025-10035 as a zero-day to create a backdoor admin account. Ionut ArghireSeptember 26, 2025
Vulnerabilities Fortra Patches Critical GoAnywhere MFT Vulnerability Tracked as CVE-2025-10035 (CVSS score of 10), the critical deserialization vulnerability could be exploited for command injection. Ionut ArghireSeptember 22, 2025
Vulnerabilities Fortra Patches Critical Vulnerability in FileCatalyst Workflow Fortra limits access to FileCatalyst Workflow database after vendor knowledgebase article leaks default credentials. Ionut ArghireAugust 30, 2024
Vulnerabilities Fortra Patches Critical SQL Injection in FileCatalyst Workflow Fortra has patched a critical-severity vulnerability in FileCatalyst Workflow leading to the creation of administrator accounts. Ionut ArghireJune 28, 2024
Vulnerabilities PoC Published for Critical Fortra Code Execution Vulnerability A critical directory traversal vulnerability in Fortra FileCatalyst Workflow could lead to remote code execution. Ionut ArghireMarch 18, 2024
Vulnerabilities PoC Code Published for Just-Disclosed Fortra GoAnywhere Vulnerability PoC code exploiting a critical Fortra GoAnywhere MFT vulnerability gets published one day after public disclosure. Ionut ArghireJanuary 24, 2024