CVE-2023-0669Disclosure(fortra / goanywhere_managed_file_transfer)

LOWCVSS 7.2 · HIGHCISA KEV

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in version 7.1.2.

0.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2023-03-03. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • goanywhere_managed_file_transfer

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
goanywhere_managed_file_transfer

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-23: 1Technical Details · 2026-08-23: 108-23
Signal classification1 categories
Disclosure
1100.0%
Referenced assets9 URLs
Full discourse1 post
  • RST Cloud@rst_cloud
    Disclosure

    #threatreport #HighCompleteness VEEAM UNDER FIRE: Understanding CVE-2026–44963 & Ransomware Group Exploit Claims | 20-08-2026 Source: https://theravenfile.com/2026/08/20/veeam-under-fire-understanding-cve-2026-44963-ransomware-group-exploit-claims/ Key details below ↓ 🧑‍💻Actors/Campaigns: Lynx_ransomware Carbanak Dragonforce Vice_society Lazarus Bluenoroff Warlock Hunters_international Teampcp 💀Threats: Lynx, Akira_ransomware, Fog_ransomware, Credential_harvesting_technique, Credential_dumping_technique, Qilin_ransomware, Rclone_tool, Conti, Blackbasta, Kerberoasting_technique, Bitsadmin_tool, Pdq_deploy_tool, Cuba_ransomware, Cobalt_strike_tool, Bughatch, Burntcigar, Metasploit_tool, Defendercontrol_tool, Veeamhax, Anydesk_tool, Simplehelp_tool, Medusa_ransomware, Clop, Lemurloot, Rhysida, Secretsdump_tool, Putty_tool, Nltest_tool, Ransomhub, Lockbit, Dcsync_technique, Gentlekiller, Av-killer, Hexkiller, Throttleblood, Havockiller, Oxideharvest, Impacket_tool, Wmiexec_tool, Netexec_tool, Inc_ransomware, Anubis, Dire_wolf, Wevtutil_tool, Shadow_copies_delete_technique, Vssadmin_tool, Everest_ransomware, Supply_chain_technique, 🎯Victims: Data backup and recovery sector 🏭Industry: Critical_infrastructure 🌐Geo: Dprk, Latin american 🔓CVEs: CVE-2023-3519 \[[Vulners](https://vulners.com/cve/CVE-2023-3519)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - citrix netscaler_application_delivery_controller (<12.1-55.297, <13.0-91.13, <13.1-37.159, <13.1-49.13) - citrix netscaler_gateway (<13.0-91.13, <13.1-49.13) CVE-2026-44963 \[[Vulners](https://vulners.com/cve/CVE-2026-44963)] - CVSS V3.1: *9.4*, - Vulners: Exploitation: True CVE-2026-12569 \[[Vulners](https://vulners.com/cve/CVE-2026-12569)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - ptc flexplm (le11.0m030, 11.1m020, 11.2.1.0, 12.0.0.0, 12.0.2.0) CVE-2023-34362 \[[Vulners](https://vulners.com/cve/CVE-2023-34362)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - progress moveit_cloud (<14.0.5.45, <14.1.6.97, <15.0.2.39) - progress moveit_transfer (<2021.0.7, <2021.1.5, <2022.0.5, <2022.1.6, <2023.0.2) CVE-2023-27532 \[[Vulners](https://vulners.com/cve/CVE-2023-27532)] - CVSS V3.1: *7.5*, - Vulners: Exploitation: True Soft: - veeam veeam_backup_\&_replication (<11.0.1.1261, 12.0.0.1420) CVE-2024-40711 \[[Vulners](https://vulners.com/cve/CVE-2024-40711)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - veeam veeam_backup_\&_replication (<12.2.0.334) CVE-2023-0669 \[[Vulners](https://vulners.com/cve/CVE-2023-0669)] - CVSS V3.1: *7.2*, - Vulners: Exploitation: True Soft: - fortra goanywhere_managed_file_transfer (<7.1.2) CVE-2025-33073 \[[Vulners](https://vulners.com/cve/CVE-2025-33073)] - CVSS V3.1: *8.8*, - Vulners: Exploitation: True Soft: - microsoft windows_10_1507 (<10.0.10240.21034) - microsoft windows_10_1607 (<10.0.14393.8148) - microsoft windows_10_1809 (<10.0.17763.7434) - microsoft windows_10_21h2 (<10.0.19044.5965) ... 📚TTPs: ⚔️Tactics: 3 🛠️Technics: 0 🤖LLM extracted TTPs:` T1068, T1078, T1210 🧨IOCs: - File: 14 - Hash: 1 💽Software: MSSQL, PostgreSQL, Hyper-V, curl, PDQ Deploy, Windows Defender, FortiGate, PsExec, MOVEit, GoAnywhere, ... 🔢Algorithms: chacha20, md5 ⚙️Win Services: SQLAgent$VEEAMSQL2008R2, VeeamTransportSvc, BackupExecJobEngine, SQLSERVERAGENT, Symantec System Recovery 📜Programming Languages: powershell #threatreport: CVE-2026-44963 is described as a critical remote code execution vulnerability affecting Veeam Backup & Replication 12.x. The flaw reportedly involves insecure deserialization and allows a low-privileged, authenticated domain user to execute arbitrary code over the network against a domain-joined Veeam backup server. Successful exploitation can result in SYSTEM-level control of the server, making the vulnerability particularly significant because backup infrastructure often provides access to sensitive data and recovery operations. The report gives the vulnerability a CVSS score of 9.4 and compares it with earlier Veeam deserialization vulnerabilities, including CVE-2024-40711. The Lynx ransomware group allegedly claimed to use a private or improved version of the vulnerability that does not require domain credentials. An underground forum advertisement similarly claimed to offer an exploit that bypasses the June 2026 patch and achieves unauthenticated SYSTEM-level remote code execution. As of mid-August 2026, these claims had not been independently verified. The report notes that there was no public technical analysis, confirmed exploitation evidence, or vendor acknowledgment demonstrating a genuine unauthenticated bypass or residual vulnerability. The claims may therefore represent negotiation tactics intended to increase ransom demands or protect an alleged exploit. The report also connects the vulnerability to a private exploit advertised in 2025, assessing that it may have been an early version of, or the same underlying issue as, CVE-2026-44963. Veeam has historically been targeted by ransomware groups, including Akira, Fog, Cuba, and FIN7, because compromising backup servers enables attackers to disrupt recovery operations before deploying ransomware. Another major Veeam attack vector is CVE-2023-27532, which can expose credentials from the Veeam backup service and database. Attackers may use these credentials for initial access or lateral movement, including through post-compromise credential-dumping activity. Regardless of whether the alleged unauthenticated exploit exists, the authenticated RCE described for CVE-2026-44963 presents a serious risk wherever domain accounts or backup infrastructure are compromised.

    Post summary

    The report discloses technical details of CVE‑2026‑44963, noting potential but unverified exploits, and highlights related Veeam vulnerabilities without confirming active attacks or providing patches.

    00000241
    779 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfortragoanywhere_managed_file_transfer---

Explore more