The creators of the GoAnywhere MFT file transfer solution are warning customers about a zero-day remote code execution vulnerability in exposed administrator consoles.
See also: Citrix: Thousands of servers at risk due to security vulnerabilities

With GoAnywhere, companies can securely share encrypted files with their partners without risking data breaches. It also offers a detailed audit trail so businesses can track who has accessed which files at any time.
Investigative journalist Brian Krebs first revealed the GoAnywhere security advisory to the world by posting a copy on Mastodon.
According to a customer who was notified of this issue, both on-premises and SaaS versions of GoAnywhere are affected.
The security advisory confirms that exploiting the system requires access to the administrator console, which should not be accessible to people outside the network.

See also: TargetCompany: Microsoft SQL servers compromised in ransomware attacks
To secure your system and prevent zero-day vulnerability exploitation, Fortra recommends that you implement the following steps without delay:
- To modify the GoAnywhere MFT, open the file “[install_dir]/adminroot/WEB_INF/web.xml” in your system file directory.
- Locate and get rid of (delete or comment out) the servlet and servlet-mapping setting highlighted in the image below.
- Restart the GoAnywhere MFT application.
To keep facilities safe, the company strongly encourages managers to conduct regular inspections:
- Investigate whether any new administrator accounts appear to have been created by an unknown source and confirm that the administrator audit log does not indicate that a disabled or non-existent superuser created this account.
- Explore the administration log to uncover user activity (Reports > Audit Logs > Administration). Discover every item created by the root.
See also: Travel company servers seized due to breach
Although the attack surface appears limited, it is important to recognize that large organizations use these products to transfer important files with their partners.
