PatchSiren cyber security CVE debrief
CVE-2025-1241 Fortra CVE debrief
Encrypted values in Fortra's GoAnywhere MFT prior to version 7.10.0 and GoAnywhere Agents prior to version 2.2.0 utilize a static IV which allows admin users to brute-force decryption of data. This vulnerability requires immediate attention from administrators to assess exposure and update decryption practices. The static IV usage enables admin users to potentially access sensitive data through brute-force decryption methods. Therefore, it is crucial to verify decryption practices and implement compensating controls where necessary.
- Vendor
- Fortra
- Product
- GoAnywhere MFT
- CVSS
- MEDIUM 5.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-21
- Original CVE updated
- 2026-09-30
- Advisory published
- 2026-04-21
- Advisory updated
- 2026-09-30
Who should care
Admin users of GoAnywhere MFT and GoAnywhere Agents should assess exposure and prioritize verification of decryption practices. This includes reviewing current decryption methods, assessing the potential impact of brute-force decryption, and implementing compensating controls where necessary. Additionally, security teams and vulnerability management teams should be aware of this vulnerability and its potential impact
Why it matters
CVE-2025-1241 allows admin users to brute-force decryption of data in Fortra's GoAnywhere MFT and GoAnywhere Agents due to static IV usage, requiring verification and potential updates to decryption practices.
- Admin users can brute-force decryption of data due to static IV usage.
- Decryption practices require verification and potential updates.
- Exposure assessment and compensating controls implementation are necessary.
Technical summary
The vulnerability in Fortra's GoAnywhere MFT and GoAnywhere Agents is due to the use of a static IV for encrypting values. This allows admin users to brute-force decryption of data, potentially leading to unauthorized access to sensitive information. The affected products are GoAnywhere MFT versions prior to 7.10.0 and GoAnywhere Agents versions prior to 2.2.0. Administrators must verify decryption practices and update systems to mitigate this vulnerability.
Defensive priority
Admin users should assess exposure and prioritize verification of decryption practices.
Recommended defensive actions
- Admin users should verify decryption practices for GoAnywhere MFT and GoAnywhere Agents.
- Review and update GoAnywhere MFT to version 7.10.0 or later and GoAnywhere Agents to version 2.2.0 or later.
- Assess exposure and implement compensating controls for decryption practices.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but vendor advisory details are limited. The NVD entry confirms the vulnerability exists in Fortra's GoAnywhere MFT prior to version 7.10.0 and GoAnywhere Agents prior to version 2.2.0. However, additional verification is required to assess the full scope of affected systems and to confirm the effectiveness of proposed mitigations.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-1241 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-1241
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-1241 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-1241
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://fortra.com/security/advisories/product-security/FI-2026-001
df4dee71-de3a-4139-9588-11b62fe6c0ff - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.