
CVE-2026-1089 User‑Controlled HTTP Header in Fortra's GoAnywhere MFT prior to version 7.10.0 allows attackers to trigger a DNS lookup, as well as DNS Rebinding and Information Disclo… https://www.cve.org/CVERecord?id=CVE-2026-1089
Post summary
The statement highlights CVE‑2026‑1089 as a user‑controlled header vulnerability in Fortra’s GoAnywhere MFT that permits DNS lookup/rebinding and info disclosure, but offers no PoC, exploit, active use, or patch details.
