PatchSiren cyber security CVE debrief
CVE-2025-14362 Fortra CVE debrief
CVE-2025-14362 is a high-severity vulnerability in Fortra's GoAnywhere Managed File Transfer. The login limit is not enforced on the SFTP service if the Web User attempting to log in is configured to use an SSH Key, making the SSH key vulnerable to brute force attacks. This issue was fixed in version 7.10.0. The vulnerability exists because when a Web User is set up to log in with an SSH Key, the usual login limit protections are bypassed, potentially allowing attackers to repeatedly try different SSH keys. Defenders should assess exposure, especially in environments using SSH key authentication, and prioritize remediation by upgrading to version 7.10.0 or later. It's crucial to
- Vendor
- Fortra
- Product
- GoAnywhere MFT
- CVSS
- HIGH 7.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-21
- Original CVE updated
- 2026-09-30
- Advisory published
- 2026-04-21
- Advisory updated
- 2026-09-30
Who should care
Defenders responsible for managing and securing file transfer services, particularly those using Fortra's GoAnywhere Managed File Transfer with SSH key authentication, should assess exposure and prioritize remediation.
Why it matters
CVE-2025-14362 is a high-severity vulnerability in Fortra's GoAnywhere Managed File Transfer that allows for brute force attacks on SSH keys when login limits are not enforced. Defenders should prioritize verifying exposure, especially in environments using SSH key authentication, and remediate vulnerable instances by upgrading to version 7.10.0 or later.
- Potential for brute force attacks on SSH keys
- Increased risk of unauthorized access to file transfer services
- Need for verification of exposure in environments using SSH key authentication
- Priority for remediation in high-risk environments
Technical summary
The vulnerability exists in the SFTP service of Fortra's GoAnywhere Managed File Transfer prior to version 7.10.0. When a Web User is configured to log in with an SSH Key, the login limit is not enforced, making the SSH key susceptible to brute force attacks.
Defensive priority
Defenders should prioritize verifying exposure and remediating vulnerable instances, especially in environments where SSH key authentication is used.
Recommended defensive actions
- Verify if GoAnywhere Managed File Transfer instances are running versions prior to 7.10.0 and are configured to use SSH key authentication.
- Assess exposure in environments where SSH key authentication is used.
- Remediate vulnerable instances by upgrading to version 7.10.0 or later.
- Monitor for potential brute force attacks on SFTP services.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its CVSS score of 7.3 and the affected versions prior to 7.10.0. The CVE Program and NVD offer official information on CVE-2025-14362, confirming the vulnerability's existence and impact. Vendor advisories also support this information, emphasizing the need for defenders to verify exposure and remediate vulnerable instances. Evidence from these sources indicates that the vulnerability allows for brute force
Sources and references
Verified primary and authoritative sources
-
CVE-2025-14362 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-14362
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-14362 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-14362
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://fortra.com/security/advisories/product-security/FI-2026-002
df4dee71-de3a-4139-9588-11b62fe6c0ff - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.