Netskope Threat Labs

SERVER-WEBAPP Fortra GoAnywhere MFT remote code execution attempt

IPS-NPA

1 SID: 61373

First seen
May 2025
Last seen
September 2026

Detects an attempt to exploit CVE-2023-0669, a remote code execution flaw that can run code on the server in Fortra GoAnywhere MFT. The flaw drove a mass exploitation campaign attributed to the CL0P ransomware group.