Fortra, LLC
First CVE: Jan 22, 2024Active for: 3 years
36
CVEs Published
More CVEs Published than 51% of tracked CNAs
12.0
Avg CVEs / Year
More Avg CVEs / Year than 58% of tracked CNAs
6.6
Avg CVSS Score
Higher Avg CVSS Score than 29% of tracked CNAs
2.8%
In CISA KEV
Higher KEV Rate than 94% of tracked CNAs
Self-Reporting Analysis
Of all the CVEs published by Fortra, LLC as a CNA, 63.9% affect products that Fortra, LLC develops as a vendor.
63.9%
36.1%
Self-reported: 23Third-party: 13
Of all the CVEs published that affect products developed by Fortra, LLC, 88.5% are self-published by Fortra, LLC as a CNA.
88.5%
11.5%
Self-published: 23Published by other CNAs: 3
Trends Over Time
The number and severity of CVEs published by Fortra, LLC over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 22, 2024
2 years ago
Most Recent CVE
Jun 23, 2026
31 days ago
Top CVEs
All CVEs published by Fortra, LLC as a CNA, regardless of affected vendor or product.
36 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-10035CRITICAL A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor | Sep 18, 2025 | 9.8 | 98 | YES | YES |
CVE-2024-0204CRITICAL Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal. | Jan 22, 2024 | 9.8 | 94 | NO | YES |
CVE-2024-5276CRITICAL A SQL Injection vulnerability in Fortra FileCatalyst Workflow allows an attacker to modify application data. Likely impacts include creation of administrative users and deletion o | Jun 25, 2024 | 9.1 | 89 | NO | YES |
CVE-2024-25153CRITICAL A directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows files to be uploaded outside of the intended ‘uploadtemp’ directory with a specially cr | Mar 13, 2024 | 9.8 | 54 | NO | NO |
CVE-2026-9862CRITICAL Fortra's
Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the servi | Jun 15, 2026 | 9.8 | 41 | NO | NO |
CVE-2026-9863HIGH Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations. A malicious or compromised leg | Jun 15, 2026 | 8.8 | 34 | NO | NO |
CVE-2024-6633CRITICAL The default credentials for the setup HSQL database (HSQLDB) for FileCatalyst Workflow are published in a vendor knowledgebase article. Misuse of these credentials could lead to a | Aug 27, 2024 | 9.8 | 31 | NO | NO |
CVE-2024-4332CRITICAL An authentication bypass vulnerability has been identified in the REST and SOAP API components of Tripwire Enterprise (TE) 9.1.0 when TE is configured to use LDAP/Active Directory | Jun 3, 2024 | 9.3 | 28 | NO | NO |
CVE-2026-12163MEDIUM Fortra File Integrity Monitoring (FIM), formerly Tripwire Enterprise, versions prior to 9.4.0.1 contain a stored cross-site scripting (XSS) vulnerability in the Asset View UI compo | Jun 23, 2026 | 4.8 | 27 | NO | NO |
CVE-2025-8450HIGH Improper Access Control issue in the Workflow component of Fortra's FileCatalyst allows unauthenticated users to upload arbitrary files via the order forms page. | Aug 19, 2025 | 8.2 | 27 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA36 CVEs
64%
17%
19%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local10 (27.8%)
Network25 (69.4%)
Unknown0 (0.0%)
Physical1 (2.8%)
Adjacent Network0 (0.0%)
Attack Complexity
Low35 (97.2%)
High1 (2.8%)
Unknown0 (0.0%)
User Interaction
None30 (83.3%)
Unknown0 (0.0%)
Required6 (16.7%)
Privileges Required
Low11 (30.6%)
High6 (16.7%)
None19 (52.8%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (36 CVEs).
CISA KEV
1 CVE
2.8% of CVEs· 94th percentile
Metasploit
2 CVEs
5.6% of CVEs· 97th percentile
Nuclei
3 CVEs
8.3% of CVEs· 95th percentile
ExploitDB
1 CVE
2.8% of CVEs· 91st percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by Fortra, LLC as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Fortra, LLC as a CNA — matched by CVE ID, not by organization name.