CVEs we hold for Fortra
Records whose assigning authority named Fortra as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-9863Core Privileged Access Manager (BoKS) upgrade tooling command injection vulnerabilityFortra Core Privileged Access Manager (BoKS)
CVE-2026-9862Core Privileged Access Manager (BoKS) autoregistration service command injection vulnerabilityFortra Core Privileged Access Manager (BoKS)
CVE-2026-12164Privilege Escalation in Fortra File Integrity Monitoring (FIM)Fortra File Integrity Monitoring (FIM)
CVE-2026-12163Stored XSS in Fortra File Integrity Monitoring (FIM)Fortra File Integrity Monitoring (FIM)
CVE-2026-1089User‑Controlled HTTP Header In Fortra's GoAnywhere MFT Allows Arbitrary DNS LookupsFortra GoAnywhere MFT
CVE-2026-0972HTML Injection possible in system generated emails in Fortra's GoAnywhere MFTFortra GoAnywhere MFT
CVE-2026-0971GoAnywhere MFT SAML Sessions do not redirect to logout URL on session timeoutFortra GoAnywhere MFT
CVE-2025-8148CVE-2025-8148 Improper Access Control in SFTP service of GoAnywhere MFTFortra GoAnywhere MFT
CVE-2025-5141Core Privileged Access Manager (BoKS) Leakage of Sensitive Data via the CacheFortra Core Privileged Access Manager (BoKS)
CVE-2025-3871Broken Access Control Leads to Limited Denial of Service in GoAnywhere MFT 7.8.0 and earlierFortra GoAnywhere MFT
CVE-2025-14362GoAnywhere MFT SFTP Service Login Vulnerable to Brute Force Attack Under Certain CircumstancesFortra GoAnywhere MFT
CVE-2025-13532Weak Password Hash in Core Privileged Access Manager (BoKS)Fortra Core Privileged Access Manager (BoKS)
CVE-2025-10035Deserialization Vulnerability in GoAnywhere MFT's License ServletFortra GoAnywhere MFT
CVE-2025-0049Disclosure of sensitive information in an error message in GoAnywhere prior to version 7.8.0Fortra GoAnywhere
CVE-2024-8264Sensitive information in agent log file when detailed logging is enabled with Robot Schedule Enterprise prior to…Fortra Robot Schedule Enterprise
CVE-2024-6633Insecure Default in FileCatalyst Workflow 5.1.6 Build 139 (and earlier)Fortra FileCatalyst Workflow
CVE-2024-6632SQL Injection in FileCatalyst Workflow 5.1.6 Build 139 (and earlier)Fortra FileCatalyst Workflow
CVE-2024-5276SQL Injection Vulnerability in FileCatalyst Workflow 5.1.6 Build 135 (and earlier)Fortra FileCatalyst Workflow
CVE-2024-5275Hard-coded password in FileCatalyst Direct 3.8.10 Build 138 TransferAgent (and earlier) and FileCatalyst Workflow 5.1.6…Fortra FileCatalyst Workflow
CVE-2024-3334USB Security Feature Bypass in Digital Guardian Windows Agent Prior to version 8.2.0Fortra Digital Guardian Agent
CVE-2024-25155Reflected Cross-Site Scripting (XSS) in FileCatalyst Direct 3.8.8 and earlierFortra FileCatalyst
CVE-2024-25153Remote Code Execution in FileCatalyst Workflow 5.x prior to 5.1.6 Build 114Fortra FileCatalyst
CVE-2024-11923Sensitive Information Disclosure in Fortra Application Hub Prior to version 1.3Fortra Application Hub
CVE-2024-11922Input Validation vulnerability in Web Client emails that do not go through Secure MailFortra GoAnywhere MFT
CVE-2024-0259Privilege Escalation in Robot Schedule Enterprise Agent for Windows prior to version 3.04Fortra Robot Schedule Enterprise Agent
CVE-2023-2989Fortra Globalscape Administration Server Out of Bounds Memory ReadFortra Globalscape EFT
39 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.