Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Fortra

Fortra Vendor Cyber Rating & Cyber Score

fortra.com

Fortra provides advanced offensive and defensive security solutions that deliver comprehensive protection across the cyber kill chain. With complete visibility across the attack chain, access to threat intelligence spanning the globe, and flexible solution delivery, Fortra customers can anticipate criminal behavior and strengthen their defenses in real time. Break the attack chain at fortra.com.


Fortra A.I CyberSecurity Scoring

Fortra
Company Information
Website:https://www.fortra.com/
Employees number:1,727
Number of followers:48,742
NAICS:5112
Industry Type:Software Development
Homepage:fortra.com
Fortra Risk Score (AI oriented)
Between 0 and 549
logo
FortraSoftware Development
Updated:
17/06/2026
100/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Fortra Global Score (TPRM)
xxxx
logo
FortraSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Fortra
FortraCritical
Current Score
100C (CRITICAL)
01000
8 incidents
-30 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
100Before Incident
Vulnerability
15 Jun 2026Fortra
Fortra: Fortra Access Manager Vulnerability Enables Remote Command Injection Attacks

Critical Command Injection Flaw in Fortra’s BoKS Exposes Privileged Access Systems

100After Incident
CRITICAL0
FOR1781699072
Critical Command Injection Flaw in Fortra’s BoKS Exposes Privileged Access Systems Fortra has disclosed a critical security vulnerability (CVE-2026-9862) in its Core Privileged Access Manager (BoKS), allowing unauthenticated remote attackers to execute arbitrary commands on affected systems. The flaw, rated CVSS 9.8, stems from an OS command injection (CWE-78) weakness in the boks_autoregisterd service, which handles host autoregistration in the privileged access management environment. The vulnerability arises from improper input neutralization during the autoregistration process, enabling attackers to craft malicious requests that inject commands. The service listens on TCP port 6507 by default, making it accessible over the network in many deployments. Exploitation requires no user interaction or prior privileges, granting attackers the ability to execute commands with the service’s permissions potentially leading to full system compromise, data manipulation, or lateral movement across networks. Fortra identified the issue on May 27, 2026, and publicly disclosed it on June 15, 2026, via advisory FI-2026-007. While patches are pending, the company recommends temporary mitigations, including: - Restricting network access to boks_autoregisterd via firewall rules or segmentation. - Disabling the service entirely by modifying the boksinit configuration file on the BoKS Master system and restarting the service. Security teams are advised to monitor for suspicious activity on port 6507, such as unexpected command execution or anomalous traffic. The flaw highlights risks posed by exposed management services and underscores the need for robust input validation in secure coding practices.
INCIDENT DETAILS -
TYPE
Command Injection
IMPACT
Systems Affected: Privileged Access Management (BoKS)Operational Impact: Full system compromise, data manipulation, lateral movement
MAY 2026
100Before Incident
APRIL 2026
100Before Incident
MARCH 2026
100Before Incident
FEBRUARY 2026
100Before Incident
JANUARY 2026
100Before Incident
Vulnerability
26 Jan 2026Fortra
SmarterTools: 6,000+ SmarterMail Servers Exposed to Actively Exploited RCE Vulnerability

Critical SmarterMail RCE Vulnerability Under Active Exploitation

100After Incident
CRITICAL0
SMA1769518747
Critical SmarterMail RCE Vulnerability Under Active Exploitation A severe remote code execution (RCE) vulnerability in SmarterTools’ SmarterMail software is being actively exploited, exposing thousands of servers worldwide. Tracked as CVE-2026-23760, the flaw allows unauthenticated attackers to execute arbitrary commands on vulnerable systems, granting full control over affected servers. Security researchers identified approximately 6,000 internet-accessible SmarterMail instances running unpatched versions, with exploitation attempts already confirmed in the wild. The Shadowserver Foundation detected the threat through version-based scans, revealing a broad attack surface across enterprises, educational institutions, and service providers. The vulnerability poses significant risks, including email interception, malware deployment, and persistent backdoor access. Organizations in healthcare, finance, government, and technology sectors are among those likely affected, given SmarterMail’s widespread adoption. Successful exploitation could lead to data exfiltration, business email compromise (BEC), and supply chain attacks. SmarterTools has released patches to address CVE-2026-23760, classified as critical due to its severity and active exploitation. The flaw’s global distribution underscores the urgency for organizations to assess, patch, and monitor their deployments to mitigate potential breaches.
INCIDENT DETAILS -
TYPE
Remote Code Execution (RCE)
IMPACT
Data Compromised: Email interception, data exfiltrationSystems Affected: SmarterMail serversOperational Impact: Full control over affected servers, potential business email compromise (BEC), supply chain attacks
DATA BREACH
Type Of Data Compromised: Email data, sensitive business informationSensitivity Of Data: HighData Exfiltration: Possible
DECEMBER 2025
100Before Incident
NOVEMBER 2025
100Before Incident
OCTOBER 2025
100Before Incident
SEPTEMBER 2025
130Before Incident
Ransomware
18 Sep 2025Fortra
Fortra

Critical Zero-Day Exploitation in Fortra’s GoAnywhere MFT Leading to Medusa Ransomware Attacks

100After Incident
CRITICAL-30
FOR0532805100725
A critical CVE-2025-10035 (CVSS 10.0) vulnerability in Fortra’s GoAnywhere Managed File Transfer (MFT) tool was actively exploited as a zero-day by threat group Storm-1175 before its patch on September 18, 2025. The flaw, a deserialization vulnerability in the License Servlet Admin Console, allowed attackers to bypass signature verification, execute arbitrary commands, and achieve remote code execution (RCE) without authentication. Post-exploitation, attackers conducted system discovery, lateral movement via RMM tools (SimpleHelp, MeshAgent), and deployed Medusa ransomware in at least one victim environment. Data exfiltration was facilitated using Rclone, while Cloudflare tunnels secured C2 communications. With 513 exposed GoAnywhere instances globally (majority in North America), the attack posed severe risks, including long-term system compromise, ransomware deployment, and potential data theft. Medusa, linked to over 300 global victims (including a US healthcare organization in 2025), leverages phishing and unpatched vulnerabilities for initial access, escalating threats to critical infrastructure.
INCIDENT DETAILS -
TYPE
Zero-day exploitationRansomware attackUnauthenticated remote code execution
MOTIVATION
Financial gain (ransomware)Data exfiltrationLong-term access for lateral movement
IMPACT
Systems Affected: 513 exposed GoAnywhere MFT instances (363 in North America)System discoveryLateral movementRansomware deployment (Medusa)Data exfiltration via RclonePotential reputational damage for FortraTrust erosion in GoAnywhere MFT users
DATA BREACH
Observed via Rclone in at least one victim environmentMedusa ransomware encryption
AUGUST 2025
120Before Incident
JULY 2025
101Before Incident
JUNE 2025
324Before Incident
Ransomware
16 Jun 2025Fortra
Fortra

Critical Zero-Day Exploitation in GoAnywhere MFT Leading to Medusa Ransomware Deployment

100After Incident
CRITICAL-224
FOR1232312100725
Fortra’s GoAnywhere Managed File Transfer (MFT) was exploited via CVE-2025-10035, a critical zero-day deserialization vulnerability (CVSS 10.0) in its License Servlet Admin Console (versions ≤ 7.8.3). The Storm-1175 threat group weaponized the flaw to achieve unauthenticated remote code execution (RCE), leading to widespread network compromise. Attackers deployed web shells (.jsp), remote monitoring tools (SimpleHelp, MeshAgent), and conducted lateral movement via RDP (mstsc.exe) while exfiltrating data using Rclone. The final payload was Medusa ransomware, encrypting systems and demanding ransom for decryption keys. The attack disrupted operations, risked sensitive data exposure, and threatened business continuity. Mitigation required emergency patching, EDR/XDR deployment, and network isolation to prevent further damage. The incident highlights severe risks from unpatched critical vulnerabilities in enterprise file-transfer systems, exposing organizations to financial loss, reputational harm, and operational shutdowns if exploited.
INCIDENT DETAILS -
TYPE
Zero-day exploitationRansomware attackUnauthorized accessData exfiltration
MOTIVATION
Financial gain (ransomware)Data theftNetwork compromise
MAY 2025
507Before Incident
Ransomware
01 May 2025Fortra
Fortra (GoAnywhere MFT)

Exploitation of CVE-2025-10035 in GoAnywhere MFT by Storm-1175 Deploying Medusa Ransomware

307After Incident
CRITICAL-200
FOR3493534100725
The CVE-2025-10035 vulnerability in Fortra’s GoAnywhere Managed File Transfer (MFT)—a critical deserialization flaw in the License Servlet—was exploited as a zero-day by the Storm-1175 ransomware group (linked to Medusa ransomware). The flaw, rated 10/10 (Critical), allows unauthenticated remote code execution (RCE) via forged license signatures, enabling attackers to inject arbitrary commands. Microsoft confirmed exploitation across multiple organizations, with at least one confirmed Medusa ransomware deployment post-compromise.Over 500 unpatched GoAnywhere MFT instances remain exposed online, risking further attacks. While Fortra released patches (7.8.4 or Sustain Release 7.6.3) on September 18, 2025, delayed updates leave systems vulnerable. The attack chain involves initial access via CVE-2025-10035, followed by ransomware deployment, potentially leading to full data encryption, operational disruption, and financial extortion demands. Organizations failing to patch or mitigate (e.g., removing public internet exposure) face severe data breaches, reputational damage, and regulatory penalties. Logs showing ‘SignedObject.getObject’ errors may indicate compromise.
INCIDENT DETAILS -
TYPE
Vulnerability ExploitationRansomware Attack
MOTIVATION
Financial Gain (Ransomware)Data Theft/Encryption
IMPACT
GoAnywhere MFT instances (500+ exposed)Potential file transfer disruptionsSystem compromise via RCEHigh (associated with ransomware deployment)
DATA BREACH
Likely (Medusa ransomware deployment)
JUNE 2023
319Before Incident
Vulnerability
16 Jun 2023Fortra
Fortra (GoAnywhere MFT)

Critical Vulnerability in Fortra's GoAnywhere MFT (CVE-2025-10035) Exploited in the Wild

315After Incident
CRITICAL-4
FOR2492024093025
The CVE-2025-10035 vulnerability in Fortra’s GoAnywhere MFT—a critical file transfer tool—was added to CISA’s Known Exploited Vulnerabilities (KEV) list with a CVSS score of 10/10. Evidence suggests active exploitation since at least September 10, 2025, though Fortra has not confirmed this publicly. The flaw allows unauthorized third-party access to systems with an internet-exposed Admin Console, risking data breaches, ransomware deployment, or APT (Advanced Persistent Threat) intrusions. Historical context links this to CVE-2023-0669, a prior GoAnywhere vulnerability exploited by the Clop ransomware gang, which breached 130+ organizations (including Hitachi, Rubrik, Rio Tinto, and government entities like Toronto and Tasmania). If exploited similarly, CVE-2025-10035 could enable mass data theft, financial fraud, or operational disruptions across thousands of vulnerable systems. While Fortra released a patch, delayed action by organizations (e.g., failing to remove public Admin Console access) increases the risk of large-scale attacks, potentially leading to regulatory penalties, reputational damage, and financial losses if customer or employee data is compromised.
INCIDENT DETAILS -
TYPE
Vulnerability ExploitationPotential Data BreachUnauthorized Access
IMPACT
GoAnywhere MFT Admin Consoles (Internet-Exposed)Potential Unauthorized AccessData Exfiltration RiskRansomware RiskPotential Reputation Damage Due to Exploitation Reports
DATA BREACH
Potential (Unconfirmed)
JANUARY 2023
660Before Incident
Ransomware
01 Jan 2023Fortra
Fortra (GoAnywhere MFT)

Fortra GoAnywhere MFT Data Breach (Clop Ransomware Attack)

253After Incident
CRITICAL-407
FOR5993659092925
In January 2023, Fortra’s GoAnywhere MFT file transfer software—a tool widely used by healthcare and financial institutions—was exploited by the Clop ransomware group, a Russian-based cybercriminal operation. The attack leveraged a zero-day vulnerability, enabling hackers to infiltrate systems and exfiltrate personal health information (PHI) of at least 5 million individuals. The breach also impacted 130 organizations, including major entities like Aetna, Community Health Systems, and NationsBenefits, exposing them to litigation. The incident led to a $20 million class-action settlement (alongside a prior $7 million subclass settlement), covering monetary compensation (up to $5,000 per victim or a flat $85), dark web monitoring, and mandated cybersecurity enhancements by defendants. The breach underscored critical failures in vulnerability management, with plaintiffs alleging negligence in safeguarding sensitive health data from unauthorized access.
INCIDENT DETAILS -
TYPE
Data BreachRansomware Attack
MOTIVATION
Financial gain (ransomware attack and data exfiltration)
IMPACT
Financial Loss: $27 million (total settlements: $20M global + $7M Brightline subclass)Data Compromised: Personal health information (PHI) of at least 5 million individualsSystems Affected: Fortra GoAnywhere MFT software used by ~130 organizationsBrand Reputation Impact: Significant (led to class-action litigation and regulatory scrutiny)Legal Liabilities: $27 million in settlements, potential ongoing legal risksIdentity Theft Risk: High (PHI of 5M+ individuals exposed)
DATA BREACH
Type Of Data Compromised: Personal Health Information (PHI)Number Of Records Exposed: 5,000,000+Sensitivity Of Data: High (health data)
JUNE 2021
760Before Incident
Ransomware
16 Jun 2021Fortra
Fortra (GoAnywhere MFT)

Exploitation of CVE-2025-10035 in Fortra's GoAnywhere MFT Leading to Medusa Ransomware Attacks

616After Incident
CRITICAL-144
FOR2002120100725
Cybercriminal group Storm-1175 exploited CVE-2025-10035, a critical vulnerability in Fortra’s GoAnywhere Managed File Transfer (MFT) solution, to deploy Medusa ransomware. The attack began as early as September 11, with threat actors leveraging the flaw for initial access, followed by lateral movement using tools like SimpleHelp and MeshAgent. Microsoft confirmed successful ransomware deployment in at least one victim environment.The vulnerability allowed attackers to maintain long-term access, perform system/user discovery, and deploy additional malware. Despite Fortra’s awareness of the bug since September 18, the company failed to disclose active exploitation, leaving organizations vulnerable for weeks. CISA later mandated federal agencies to patch by October 20, while security firm watchTowr warned of ongoing 'silent assaults' targeting GoAnywhere users.Medusa ransomware, linked to over 300 attacks on critical infrastructure since 2021, has previously breached Minneapolis Public Schools (exposing 100,000+ records), government agencies in the Philippines/France, and NASCAR. The attack’s scale suggests widespread data compromise, though Fortra has not clarified how threat actors obtained private keys for exploitation or the full extent of the damage.
INCIDENT DETAILS -
TYPE
RansomwareVulnerability ExploitationData Breach
MOTIVATION
Financial GainData TheftDisruption
DATA BREACH
Sensitive Student Documents (Minneapolis Public Schools)Potential PII and Corporate Data (Other Victims)Number Of Records Exposed: 100,000+ (Minneapolis Public Schools alone)Sensitivity Of Data: High (includes PII, student records, government data)

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Fortra ?
?
What was Fortra's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Fortra's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Fortra's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Fortra's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Fortra's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Fortra's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Fortra's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Fortra's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Fortra's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Fortra's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Fortra's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Fortra's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Fortra ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Fortra's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?