A directory traversal flaw in the ftpservlet allows unauthenticated attackers to upload malicious JSP files to the web server's root. This grants them full control to execute commands and deploy web shells.

March 18, 2024. A critical vulnerability in the Fortra FileCatalyst managed file transfer (MFT) service could enable remote code e... SC Media Critical Vulnerability in FileCatalyst Workflow (CVE-2024-5276) On June 25th, software company Fortra disclosed a critical severity vulnerability in their managed file transfer software applicat... Beazley Security CVE-2024-25153: RCE in Fortra FileCatalyst - LRQA Mar 13, 2024 —

Attackers can gain access to the large, often sensitive files typically handled by FileCatalyst.

If you are a FileCatalyst user, here are some steps you can take: