Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Fortra, LLC

First CVE: Feb 6, 2023Active for: 3 yearsTotal CVEs: 26
66.8
VTI Score
TOP TARGET

Fortra, LLC operates a focused portfolio of secure file-transfer, workflow automation, and job-scheduling products that handle sensitive enterprise data flows, positioning these applications as high-value targets despite their narrow product scope. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, with a moderate tendency toward confirmed in-the-wild exploitation and inclusion in CISA's Known Exploited Vulnerabilities catalog. The recurring exposure centers on products such as GoAnywhere Managed File Transfer, FileCatalyst Workflow and Direct, Robot Schedule, and DeliverNow, and clusters persistently around input-handling and data-processing weaknesses including SQL injection, unsafe deserialization, path traversal, cross-site scripting, and downstream injection flaws that are endemic to data-movement middleware. Defenders should treat Fortra disclosures as high-priority for any deployment handling sensitive file operations or automation workflows, as the combination of serious severity, prompt exploit availability, and historical in-the-wild activity makes these vulnerabilities operationally urgent. Current exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.

FAUCET AI Generated
26
Total CVEs
More Total CVEs than 97% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
7.7%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Fortra, LLC over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 6, 2023
3 years ago
Most Recent CVE
Jun 23, 2026
31 days ago

Self-Reporting Analysis

Of all the CVEs published by Fortra, LLC as a CNA, 63.9% affect products that Fortra, LLC develops as a vendor.

63.9%
36.1%
Self-reported: 23 (63.9%)
Third-party: 13 (36.1%)

Of all the CVEs published that affect products developed by Fortra, LLC, 88.5% are self-published by Fortra, LLC as a CNA.

88.5%
11.5%
Self-published: 23 (88.5%)
Other CNAs: 3 (11.5%)

Products(8 total)

Top CVEs

Signals from CVEs in this vendor scope (26 CVEs).

26 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-10035CRITICAL
A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor
Sep 18, 20259.898YESYES
CVE-2023-0669HIGH
Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary at
Feb 6, 20237.298YESYES
CVE-2024-0204CRITICAL
Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal.
Jan 22, 20249.894NOYES
CVE-2024-5276CRITICAL
A SQL Injection vulnerability in Fortra FileCatalyst Workflow allows an attacker to modify application data.  Likely impacts include creation of administrative users and deletion o
Jun 25, 20249.189NOYES
CVE-2024-25153CRITICAL
A directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows files to be uploaded outside of the intended ‘uploadtemp’ directory with a specially cr
Mar 13, 20249.854NONO
CVE-2024-6633CRITICAL
The default credentials for the setup HSQL database (HSQLDB) for FileCatalyst Workflow are published in a vendor knowledgebase article. Misuse of these credentials could lead to a
Aug 27, 20249.831NONO
CVE-2021-26837CRITICAL
SQL Injection vulnerability in SearchTextBox parameter in Fortra (Formerly HelpSystems) DeliverNow before version 1.2.18, allows attackers to execute arbitrary code, escalate privi
Sep 19, 20239.828NONO
CVE-2026-12163MEDIUM
Fortra File Integrity Monitoring (FIM), formerly Tripwire Enterprise, versions prior to 9.4.0.1 contain a stored cross-site scripting (XSS) vulnerability in the Asset View UI compo
Jun 23, 20264.827NONO
CVE-2026-12164MEDIUM
Fortra File Integrity Monitoring (FIM), formerly Tripwire Enterprise, versions prior to 9.4.0 may assign incorrect or elevated effective permissions to users created by the tetool
Jun 23, 20264.426NONO
CVE-2024-6632HIGH
A vulnerability exists in FileCatalyst Workflow whereby a field accessible to the super admin can be used to perform an SQL injection attack which can lead to a loss of confidentia
Aug 27, 20247.224NONO
View all 26 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products26 CVEs
62%
15%
23%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local4 (15.4%)
Network21 (80.8%)
Unknown0 (0.0%)
Physical1 (3.8%)
Adjacent Network0 (0.0%)
Attack Complexity
Low25 (96.2%)
High1 (3.8%)
Unknown0 (0.0%)
User Interaction
None21 (80.8%)
Unknown0 (0.0%)
Required5 (19.2%)
Privileges Required
Low6 (23.1%)
High7 (26.9%)
None13 (50.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (26 CVEs).

CISA KEV
2 CVEs
7.7% of CVEs· 100th percentile
Metasploit
3 CVEs
11.5% of CVEs· 98th percentile
Nuclei
4 CVEs
15.4% of CVEs· 97th percentile
ExploitDB
2 CVEs
7.7% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Fortra, LLC.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Fortra, LLC — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Fortra, LLC's Products

View all 4 CNAs →

Top CWEs