Inadequate Encryption Strength in GoAnywhere MFT - CVE-2025-1241
Published: June 19, 2026
GoAnywhere MFT
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to inadequate encryption strength in the encryption implementation when processing encrypted values. A remote privileged user can brute-force decryption of data to disclose sensitive information.
The issue is caused by the use of a static IV.