FI-2026-006 - HTML Injection possible in system generated emails in Fortra's GoAnywhere MFT
Severity
Medium
Published Date
22-Apr-2026
Updated Date
22-Apr-2026
Vulnerabilities
CVE-2026-0972
Notes
Description
HTML injection is possible in system generated emails in Fortra's GoAnywhere MFT prior to 7.10.0.
Note: The title, details, and description of this CVE were corrected post-publishing.
Vulnerabilities
Acknowledgements
Fortra would like to thank the following individuals:
- Philipp Schweinzer , SBA Research (https://www.sba-research.org/)