High severity7.3NVD Advisory· Published Apr 21, 2026· Updated Apr 23, 2026
CVE-2025-14362
CVE-2025-14362
Description
The login limit is not enforced on the SFTP service of Fortra's GoAnywhere MFT prior to 7.10.0 if the Web User attempting to be logged in to is configured to log in with an SSH Key, making the SSH key vulnerable to being guessed via Brute Force.
Affected products
1- cpe:2.3:a:fortra:goanywhere_managed_file_transfer:*:*:*:*:*:*:*:*Range: <7.10.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- fortra.com/security/advisories/product-security/FI-2026-002nvdVendor Advisory
News mentions
0No linked articles in our index yet.