Fortra, LLC operates a focused portfolio of secure file-transfer, workflow automation, and job-scheduling products that handle sensitive enterprise data flows, positioning these applications as high-value targets despite their narrow product scope. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, with a moderate tendency toward confirmed in-the-wild exploitation and inclusion in CISA's Known Exploited Vulnerabilities catalog. The recurring exposure centers on products such as GoAnywhere Managed File Transfer, FileCatalyst Workflow and Direct, Robot Schedule, and DeliverNow, and clusters persistently around input-handling and data-processing weaknesses including SQL injection, unsafe deserialization, path traversal, cross-site scripting, and downstream injection flaws that are endemic to data-movement middleware. Defenders should treat Fortra disclosures as high-priority for any deployment handling sensitive file operations or automation workflows, as the combination of serious severity, prompt exploit availability, and historical in-the-wild activity makes these vulnerabilities operationally urgent. Current exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fortra, LLC over time
Of all the CVEs published by Fortra, LLC as a CNA, 63.9% affect products that Fortra, LLC develops as a vendor.
Of all the CVEs published that affect products developed by Fortra, LLC, 88.5% are self-published by Fortra, LLC as a CNA.
Signals from CVEs in this vendor scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-10035CRITICAL A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor | Sep 18, 2025 | 9.8 | 98 | YES | YES |
CVE-2023-0669HIGH Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary at | Feb 6, 2023 | 7.2 | 98 | YES | YES |
CVE-2024-0204CRITICAL Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal. | Jan 22, 2024 | 9.8 | 94 | NO | YES |
CVE-2024-5276CRITICAL A SQL Injection vulnerability in Fortra FileCatalyst Workflow allows an attacker to modify application data. Likely impacts include creation of administrative users and deletion o | Jun 25, 2024 | 9.1 | 89 | NO | YES |
CVE-2024-25153CRITICAL A directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows files to be uploaded outside of the intended ‘uploadtemp’ directory with a specially cr | Mar 13, 2024 | 9.8 | 54 | NO | NO |
CVE-2024-6633CRITICAL The default credentials for the setup HSQL database (HSQLDB) for FileCatalyst Workflow are published in a vendor knowledgebase article. Misuse of these credentials could lead to a | Aug 27, 2024 | 9.8 | 31 | NO | NO |
CVE-2021-26837CRITICAL SQL Injection vulnerability in SearchTextBox parameter in Fortra (Formerly HelpSystems) DeliverNow before version 1.2.18, allows attackers to execute arbitrary code, escalate privi | Sep 19, 2023 | 9.8 | 28 | NO | NO |
CVE-2026-12163MEDIUM Fortra File Integrity Monitoring (FIM), formerly Tripwire Enterprise, versions prior to 9.4.0.1 contain a stored cross-site scripting (XSS) vulnerability in the Asset View UI compo | Jun 23, 2026 | 4.8 | 27 | NO | NO |
CVE-2026-12164MEDIUM Fortra File Integrity Monitoring (FIM), formerly Tripwire Enterprise, versions prior to 9.4.0 may assign incorrect or elevated effective permissions to users created by the tetool | Jun 23, 2026 | 4.4 | 26 | NO | NO |
CVE-2024-6632HIGH A vulnerability exists in FileCatalyst Workflow whereby a field accessible to the super admin can be used to perform an SQL injection attack which can lead to a loss of confidentia | Aug 27, 2024 | 7.2 | 24 | NO | NO |
Signals from CVEs in this vendor scope (26 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fortra, LLC.
Media articles that mention a CVE ID that affects a product developed by Fortra, LLC — matched by CVE ID, not by vendor name.