GoAnywhere MFT’s ‘Secure Folder’ Had a Hidden Exit

A GoAnywhere MFT user with Secure Folders and Secure Mail access could escape their assigned folder and read other server files. Fortra has a fix.

A GoAnywhere MFT user with Secure Folders and Secure Mail access could escape their assigned folder and read other server files. Fortra has a fix.

CISA says attackers are exploiting CVE-2026-85706, a CVSS 10 GitLab flaw that can expose arbitrary server files without authentication. Self-managed operators need to update and investigate.

Knowns before 0.30.0 can expose an unauthenticated management API on every network interface. One API call can then create a public tunnel, while a second vulnerability allows arbitrary files to be overwritten.

SABnzbd 5.1.2 fixes a critical unauthenticated route to code execution, a malicious-download path traversal that can poison trusted job state, and a separate authentication bypass. Internet-facing WebUIs are urgent, but the download-processing flaw can also affect local installations.

Adobe fixed 13 ColdFusion vulnerabilities, including six CVSS 10 code-execution flaws. One path-traversal issue was already under attack.