Fortra GoAnywhere MFT was exploited through an authentication bypass that exposed the administrative console, chained with an insecure-deserialization flaw in that console that executed attacker-controlled objects, yielding remote code execution on the appliance. The admin-console exposure stemmed from a licensing or servlet endpoint reachable without authentication.
GoAnywhere chain:
- Authentication bypass exposing the admin console endpoint
- Insecure deserialization in the admin interface -> remote code execution
- Appliance compromise and bulk data access
Exploitation notes#
- The bypass hinges on reaching an admin servlet or endpoint that should be internal; the fix guidance was to restrict that path.
- Deserialization gives clean RCE once the admin surface is reachable, the same pattern as other MFT compromises.
- Both internet-facing and internally-exposed admin consoles are in scope, so segmentation matters to reachability.