<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>0dayNews — Fortra</title><description>Security advisories covering Fortra products — including BoKS ServerControl, Cobalt Strike, GoAnywhere, and other enterprise security software acquired under the HelpSystems umbrella. Combined article + CVE feed for the Fortra beat.</description><link>https://0daynews.com/</link><language>en-us</language><item><title>Fortra Fixes Critical Bugs in BoKS PAM Platform</title><link>https://0daynews.com/articles/2026-10-03-fortra-boks-critical-patches/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-10-03-fortra-boks-critical-patches/</guid><description>Fortra has patched critical vulnerabilities in BoKS ServerControl, its Unix/Linux privileged access management platform. The flaws include authentication bypass, shell command execution, and memory corruption.</description><pubDate>Sat, 03 Oct 2026 16:30:00 GMT</pubDate><category>Fortra</category><category>article</category></item><item><title>CVE-2022-39197 — Fortra Cobalt Strike Teamserver Cross-Site Scripting (XSS) Vulnerability</title><link>https://0daynews.com/cve/cve-2022-39197/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-39197/</guid><description>Fortra Cobalt Strike contains a cross-site scripting (XSS) vulnerability in Teamserver that would allow an attacker to set a malformed username in the Beacon configuration, allowing them to execute code remotely.</description><pubDate>Sat, 03 Oct 2026 00:00:00 GMT</pubDate><category>Fortra</category><category>medium</category><category>cve</category></item><item><title>CVE-2022-42948 — Fortra Cobalt Strike User Interface Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2022-42948/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-42948/</guid><description>Fortra Cobalt Strike User Interface contains an unspecified vulnerability rooted in Java Swing that may allow remote code execution.</description><pubDate>Sat, 03 Oct 2026 00:00:00 GMT</pubDate><category>Fortra</category><category>critical</category><category>cve</category></item><item><title>CVE-2023-0669 — Fortra GoAnywhere MFT Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2023-0669/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-0669/</guid><description>Fortra (formerly, HelpSystems) GoAnywhere MFT contains a pre-authentication remote code execution vulnerability in the License Response Servlet due to deserializing an attacker-controlled object.</description><pubDate>Sat, 03 Oct 2026 00:00:00 GMT</pubDate><category>Fortra</category><category>high</category><category>cve</category></item><item><title>CVE-2025-10035 — Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability</title><link>https://0daynews.com/cve/cve-2025-10035/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-10035/</guid><description>Fortra GoAnywhere MFT contains a deserialization of untrusted data vulnerability allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.</description><pubDate>Sat, 03 Oct 2026 00:00:00 GMT</pubDate><category>Fortra</category><category>critical</category><category>cve</category></item></channel></rss>