Vendor

Fortra

As of , 4 Fortra vulnerabilities are on CISA's list of exploited vulnerabilities, 2 of them used in ransomware campaigns; 0 were added in 2026. Patch first: CVE-2023-0669.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2023-0669Remote Code ExecutionFortra GoAnywhere MFTPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
2CVE-2025-10035Deserialization of Untrusted DataFortra GoAnywhere MFTPatch this weekRansomware use; EPSS 0.990.99
3CVE-2022-39197Teamserver Cross-Site Scripting (XSS)Fortra Cobalt StrikePatch soon0.46
4CVE-2022-42948User Interface Remote Code ExecutionFortra Cobalt StrikePatch soon0.03

Products

  • Cobalt Strike2 entries
  • GoAnywhere MFT2 entries

Added each year

1232023: 3320232024: nonenone20242025: 1120252026: nonenone2026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20233
2024none
20251
2026none

Used in ransomware

Changes CISA made to these entries

  1. CVE-2025-10035 Fortra GoAnywhere MFTRansomware use: Unknown to Known.

Every change we recorded