PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-14362 Fortra CVE debrief

CVE-2025-14362 is a high-severity vulnerability in Fortra's GoAnywhere Managed File Transfer. The login limit is not enforced on the SFTP service if the Web User attempting to log in is configured to use an SSH Key, making the SSH key vulnerable to brute force attacks. This issue was fixed in version 7.10.0. The vulnerability exists because when a Web User is set up to log in with an SSH Key, the usual login limit protections are bypassed, potentially allowing attackers to repeatedly try different SSH keys. Defenders should assess exposure, especially in environments using SSH key authentication, and prioritize remediation by upgrading to version 7.10.0 or later. It's crucial to

Vendor
Fortra
Product
GoAnywhere MFT
CVSS
HIGH 7.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-21
Original CVE updated
2026-09-30
Advisory published
2026-04-21
Advisory updated
2026-09-30

Who should care

Defenders responsible for managing and securing file transfer services, particularly those using Fortra's GoAnywhere Managed File Transfer with SSH key authentication, should assess exposure and prioritize remediation.

Why it matters

CVE-2025-14362 is a high-severity vulnerability in Fortra's GoAnywhere Managed File Transfer that allows for brute force attacks on SSH keys when login limits are not enforced. Defenders should prioritize verifying exposure, especially in environments using SSH key authentication, and remediate vulnerable instances by upgrading to version 7.10.0 or later.

  • Potential for brute force attacks on SSH keys
  • Increased risk of unauthorized access to file transfer services
  • Need for verification of exposure in environments using SSH key authentication
  • Priority for remediation in high-risk environments

Technical summary

The vulnerability exists in the SFTP service of Fortra's GoAnywhere Managed File Transfer prior to version 7.10.0. When a Web User is configured to log in with an SSH Key, the login limit is not enforced, making the SSH key susceptible to brute force attacks.

Defensive priority

Defenders should prioritize verifying exposure and remediating vulnerable instances, especially in environments where SSH key authentication is used.

Recommended defensive actions

  • Verify if GoAnywhere Managed File Transfer instances are running versions prior to 7.10.0 and are configured to use SSH key authentication.
  • Assess exposure in environments where SSH key authentication is used.
  • Remediate vulnerable instances by upgrading to version 7.10.0 or later.
  • Monitor for potential brute force attacks on SFTP services.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its CVSS score of 7.3 and the affected versions prior to 7.10.0. The CVE Program and NVD offer official information on CVE-2025-14362, confirming the vulnerability's existence and impact. Vendor advisories also support this information, emphasizing the need for defenders to verify exposure and remediate vulnerable instances. Evidence from these sources indicates that the vulnerability allows for brute force

Sources and references

Verified primary and authoritative sources

  • CVE-2025-14362 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-14362

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-14362 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-14362

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://fortra.com/security/advisories/product-security/FI-2026-002

    df4dee71-de3a-4139-9588-11b62fe6c0ff - Vendor Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.