
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-1241 is a cryptographic weakness in Fortra's GoAnywhere Managed File Transfer (MFT) and GoAnywhere Agents that allows admin users to brute-force decrypt sensitive encrypted data due to the use of a static Initialization Vector (IV). The vulnerability affects GoAnywhere MFT versions prior to 7.10.0 and GoAnywhere Agents versions prior to 2.2.0, running on Windows, Linux, and macOS platforms. It was disclosed on April 21, 2026, with NVD initial analysis completed on April 23, 2026. The CVSS v3.1 base score is 4.9 (Medium) per NIST/NVD, and 5.8 (Medium) per Fortra as the CNA (Github Advisory, Fortra Advisory).
The root cause is classified as CWE-326 (Inadequate Encryption Strength): the affected products use a static IV in their encryption scheme, which undermines the security of the cipher by making encrypted outputs deterministic and predictable for identical plaintext inputs. A static IV in block cipher modes (such as CBC or CTR) eliminates the randomness that prevents pattern analysis and brute-force attacks against ciphertext. An attacker with admin-level access to the system can leverage this weakness to systematically brute-force the decryption of stored or transmitted encrypted values. No public proof-of-concept exploit code has been identified at this time (Github Advisory, Fortra Advisory).
Successful exploitation results in a high confidentiality impact, as an admin-level attacker can brute-force decrypt sensitive data protected by the flawed encryption scheme — potentially exposing credentials, file transfer configurations, or other sensitive information stored within GoAnywhere MFT or its agents. There is no integrity or availability impact associated with this vulnerability. The scope of impact is limited to the affected component under NIST's scoring, though Fortra's own scoring indicates a potential scope change, suggesting encrypted data from one component could be exposed in another context (Fortra Advisory, Github Advisory).
Fortra has released patched versions addressing this vulnerability: GoAnywhere MFT version 7.10.0 and GoAnywhere Agents version 2.2.0. Organizations should upgrade to these versions or later as the primary remediation. No specific configuration-based workarounds have been publicly documented; restricting admin account access and enforcing strong authentication controls can reduce the risk of exploitation in the interim (Fortra Advisory, Github Advisory).
The vulnerability received routine coverage from vulnerability tracking platforms and security aggregators, including CISA's weekly vulnerability bulletin for the week of April 20, 2026. No notable independent researcher commentary, vendor statements beyond the official advisory, or significant social media discussion has been identified. Community reaction appears muted, consistent with the moderate severity rating and the requirement for admin-level privileges to exploit (CISA Bulletin, RedPacket Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."