On September 9, 2026, Fortra published a security advisory about a path traversal flaw in GoAnywhere MFT. Tracked as CVE-2026-15913, the issue affects the /attachRemoteFiles endpoint and versions before 7.10.2. The Canadian Centre for Cyber Security relayed the alert on September 10.
The documented risk is arbitrary file read through a Web User with a specific combination of permissions. The advisory does not publish a victim list or evidence that a named organisation was exploited: the priority is to check scope and patch without turning a vulnerability advisory into an unverified breach claim.
What Fortra confirmed
Fortra rates the vulnerability High and classifies it as CWE-23 relative path traversal. The issue is in GoAnywhere MFT’s /attachRemoteFiles endpoint. In affected versions, a Web User with both Secure Folders and Secure Mail permissions can escape the sandboxed home directory and read arbitrary files.
The published CVSS score is 7.7, with a network attack vector, low complexity, and required privileges. The score describes potential impact; it does not prove that a file was read in every exposed deployment.
Who should check their deployment
The stated scope is GoAnywhere MFT before version 7.10.2. Inventory should include on-premise installations, standby instances, test environments, and systems operated by an integrator. Verify the product version rather than relying only on whether an administration interface is present.
Fortra says MFT as a Service customers are protected from exploitation through environmental controls. That statement applies to that service model; confirm your deployment type and ask the provider or administrator which version and controls apply to your instance.
The fix and priority checks
The official remediation is to upgrade to GoAnywhere MFT 7.10.2 or later. Before and after the change, record the installed version, correction time, and instances covered. If an upgrade must wait, reduce exposure according to Fortra’s procedures and review Web User accounts that combine the two permissions named in the advisory.
After remediation, search for requests to /attachRemoteFiles, unusual paths, and reads outside the expected directory. Correlate those signals with authentication logs, account ownership, and transfer schedules; no single indicator proves compromise.
What to do if exposure is possible
Preserve logs before rotation and avoid changes that could overwrite useful evidence. Compare observed access with legitimate work performed by Web Users holding Secure Folders and Secure Mail. If abnormal reads are confirmed or strongly suspected, isolate the instance under your response plan, reassess secrets accessible from the server, and involve the people responsible for the investigation.
The documented flaw is a file-read issue; that alone does not establish code execution, complete exfiltration, or compromise of every account. Separating what the advisory proves from what local logs can establish prevents both under- and overestimating the incident.
How Soclyde fits
Soclyde does not patch GoAnywhere MFT, collect its logs, or replace incident response. Its role is around access that may need to be reassessed after exposure: generate unique secrets, keep them in a local-first encrypted vault, and make rotation easier when an administrative or integration account must be replaced.
That separation limits reuse of one secret across GoAnywhere MFT, email, and other services. It does not make a vulnerable instance safe: upgrading, reviewing logs, and investigating exposure remain the priorities.
Key takeaways
CVE-2026-15913 affects /attachRemoteFiles in GoAnywhere MFT before 7.10.2. The documented scenario requires a Web User with Secure Folders and Secure Mail, but can allow escape from the sandbox and arbitrary file reads. Upgrade, review permissions, and search for abnormal access without treating compromise as established.
To reduce the impact of reused secrets during remediation, read the secure password generator guide or contact Soclyde.



