Skip to content
English

Products › IT administration and security

IT administration and security

Managed file transfer (MFT)

Platforms for exchanging and sharing files with outside parties, often exposed to the internet.

For example: MOVEit, GoAnywhere, CrushFTP, Cleo.

Category RSS feed

Affected brands

In alphabetical order, with their number of vulnerabilities in this category.

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

See also

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.

  1. Rank 1ownCloud Server

    CVE-2023-49105

    Hunt for compromise (CISA)CVE from 2023, added in 2026

    ownCloud Improper Authentication Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 27, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  2. Rank 2Gladinet CentreStack / Triofox

    CVE-2025-14611

    Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Dec 15, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  3. Rank 3Fortra GoAnywhere MFT

    CVE-2025-10035

    Ransomware

    Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Sep 29, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  4. Rank 4Gladinet CentreStack / Triofox

    CVE-2025-12480

    Gladinet Triofox Improper Access Control Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Nov 12, 2025
    CISA deadline
    21 days
    CVSS severity
    9.1 (critical)
  5. Rank 5Soliton Systems FileZen

    CVE-2026-25108

    Soliton Systems K.K FileZen OS Command Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 24, 2026
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  6. Rank 6SolarWinds Serv-U

    CVE-2026-28318

    SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 5, 2026
    CISA deadline
    14 days
    CVSS severity
    7.5 (high)
  7. Rank 7Gladinet CentreStack / Triofox

    CVE-2025-11371

    Gladinet CentreStack and Triofox Files or Directories Accessible to External Parties Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Nov 4, 2025
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  8. Rank 8Wing FTP Server

    CVE-2025-47813

    Wing FTP Server Information Disclosure Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 16, 2026
    CISA deadline
    14 days
    CVSS severity
    4.3 (medium)
  9. Rank 9Wing FTP Server

    CVE-2025-47812

    Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 14, 2025
    CISA deadline
    21 days
    CVSS severity
    10.0 (critical)
  10. Rank 10CrushFTP

    CVE-2024-4040

    CrushFTP VFS Sandbox Escape Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 24, 2024
    CISA deadline
    7 days
    CVSS severity
    10.0 (critical)
Show 23 more vulnerabilities
  1. Rank 11SolarWinds Serv-U

    CVE-2021-35211

    Ransomware

    SolarWinds Serv-U Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    10.0 (critical)
  2. Rank 12CrushFTP

    CVE-2025-54309

    CrushFTP Unprotected Alternate Channel Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 22, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  3. Rank 13Gladinet CentreStack / Triofox

    CVE-2025-30406

    Gladinet CentreStack and Triofox Use of Hard-coded Cryptographic Key Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 8, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  4. Rank 14CrushFTP

    CVE-2025-31161

    Ransomware

    CrushFTP Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 7, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  5. Rank 15Cleo Harmony / VLTrader / LexiCom

    CVE-2024-55956

    Ransomware

    Cleo Multiple Products Unauthenticated File Upload Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 17, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  6. Rank 16Cleo Harmony / VLTrader / LexiCom

    CVE-2024-50623

    Ransomware

    Cleo Multiple Products Unrestricted File Upload Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 13, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  7. Rank 17ProjectSend

    CVE-2024-11680

    ProjectSend Improper Authentication Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 3, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  8. Rank 18Rejetto HTTP File Server (HFS)

    CVE-2024-23692

    Ransomware

    Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 9, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  9. Rank 19Citrix ShareFile

    CVE-2023-24489

    Citrix Content Collaboration ShareFile Improper Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 16, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  10. Rank 20Progress MOVEit Transfer

    CVE-2023-34362

    Ransomware

    Progress MOVEit Transfer SQL Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 2, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  11. Rank 21IBM Aspera Faspex

    CVE-2022-47986

    Ransomware

    IBM Aspera Faspex Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 21, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  12. Rank 22Rejetto HTTP File Server (HFS)

    CVE-2014-6287

    CVE from 2014, added in 2022

    Rejetto HTTP File Server (HFS) Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  13. Rank 23Citrix ShareFile

    CVE-2021-22941

    Ransomware

    Citrix ShareFile Improper Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  14. Rank 24Kiteworks (Accellion) FTA (File Transfer Appliance)

    CVE-2021-27101

    Ransomware

    Accellion FTA SQL Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  15. Rank 25Kiteworks (Accellion) FTA (File Transfer Appliance)

    CVE-2021-27103

    Ransomware

    Accellion FTA Server-Side Request Forgery (SSRF) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  16. Rank 26Kiteworks (Accellion) FTA (File Transfer Appliance)

    CVE-2021-27104

    Ransomware

    Accellion FTA OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  17. Rank 27Progress WS_FTP Server

    CVE-2023-40044

    Ransomware

    Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 5, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  18. Rank 28Kiteworks (Accellion) FTA (File Transfer Appliance)

    CVE-2021-27102

    Ransomware

    Accellion FTA OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  19. Rank 29North Grid Proself

    CVE-2023-45727

    North Grid Proself Improper Restriction of XML External Entity (XXE) Reference Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 3, 2024
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  20. Rank 30SolarWinds Serv-U

    CVE-2024-28995

    SolarWinds Serv-U Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 17, 2024
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  21. Rank 31ownCloud Server

    CVE-2023-49103

    ownCloud graphapi Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 30, 2023
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  22. Rank 32Fortra GoAnywhere MFT

    CVE-2023-0669

    Ransomware

    Fortra GoAnywhere MFT Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 10, 2023
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  23. Rank 33SolarWinds Serv-U

    CVE-2021-35247

    SolarWinds Serv-U Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 21, 2022
    CISA deadline
    14 days
    CVSS severity
    5.3 (medium)

Follow and verify

Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).

Indicative classification, based on the vendor and product names given by CISA. How products are classified.