Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to patched version.
Vendor Workaround
Restrict access to Admin Client.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 23 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apple
Apple macos Fortra goanywhere Agents Fortra goanywhere Managed File Transfer Linux Linux linux Kernel Microsoft Microsoft windows |
|
| CPEs | cpe:2.3:a:fortra:goanywhere_agents:*:*:*:*:*:*:*:* cpe:2.3:a:fortra:goanywhere_managed_file_transfer:*:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Apple
Apple macos Fortra goanywhere Agents Fortra goanywhere Managed File Transfer Linux Linux linux Kernel Microsoft Microsoft windows |
Wed, 22 Apr 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fortra
Fortra goanywhere Mft |
|
| Vendors & Products |
Fortra
Fortra goanywhere Mft |
Wed, 22 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 21 Apr 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Encrypted values in Fortra's GoAnywhere MFT prior to version 7.10.0 and GoAnywhere Agents prior to version 2.2.0 utilize a static IV which allows admin users to brute-force decryption of data. | |
| Title | Encryption vulnerable to brute-force decryption in GoAnywhere MFT | |
| Weaknesses | CWE-326 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Fortra
Published:
Updated: 2026-04-21T19:33:03.005Z
Reserved: 2025-02-11T23:19:04.818Z
Link: CVE-2025-1241
Updated: 2026-04-21T19:32:58.757Z
Status : Analyzed
Published: 2026-04-21T15:16:35.320
Modified: 2026-04-23T14:12:22.117
Link: CVE-2025-1241
No data.
OpenCVE Enrichment
Updated: 2026-04-22T11:46:30Z