CVE-2023-0669
Exploited in the Wild
✓ Confirmed 0-Day
Triaged: March 20, 2026
12 articles
EPSS Score
Source: FIRST.org · 2026-05-24
94.38%
probability
This CVE has a 94.38% probability
of being exploited in the next 30 days.
0%
Top 100.0th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Attack Intelligence
Exploits & PoC
Avento/CVE-2023-0669
GoAnywhere MFT CVE-2023-0669 LicenseResponseServlet Deserialization Vulnerabilities Python RCE PoC(Proof of Concept)
8
1 repo — triés par ⭐
Rechercher sur GitHub ↗
2023 Threat Landscape Year in Review: If Everything Is Critical, Nothing Is
Qualys
Dec 19, 2023
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations
Qualys
May 08, 2025
Hatch Bank discloses data breach after GoAnywhere MFT hack
BleepingComputer
Mar 02, 2023
CISA Warns of Active Attacks Exploiting Fortra MFT, TerraMaster NAS, and Intel Driver Flaws
TheHackerNews
Fortra shares findings on GoAnywhere MFT zero-day attacks
BleepingComputer
Apr 19, 2023
Hitachi Energy confirms data breach after Clop GoAnywhere attacks
BleepingComputer
Mar 17, 2023
Forta GoAnywhere Zero-Day Exploited By Threat Actors
Qualys
Feb 15, 2023
Clop ransomware claims Saks Fifth Avenue, retailer says mock data stolen
BleepingComputer
Mar 21, 2023
Signal Intelligence
Confidence
92%
EPSS
94.38%
Mentions
12
Last Seen
May 08, 2025
CNA Information
Analyst Note
CVE-2023-0669 is explicitly identified as a zero-day RCE vulnerability in Fortra's GoAnywhere MFT tool with active ransomware exploitation documented. TheHackerNews article directly states 'zero-day remote code execution (RCE) vulnerability' and 'active exploitation by ransomware actors,' confirming exploitation in the wild prior to or concurrent with patch availability.
Threat Actors 16
Lazarus Group
apt_group
Information theft and espionage
🇰🇵 KP
Turla Group
apt_group
Information theft and espionage
Russian Federation
APT 29
apt_group
Information theft and espionage
🇷🇺 RU
Cobalt
apt_group
Financial crime
🇷🇺 RU
Cron
apt_group
🇷🇺 RU
SaintBear
apt_group
Information theft and espionage
🇷🇺 RU
APT3
apt_group
Information theft and espionage
🇨🇳 CN
ELECTRUM
apt_group
Information theft and espionage
🇷🇺 RU
TA505
apt_group
Financial gain
🇷🇺 RU
Infy
apt_group
Information theft and espionage
🇮🇷 IR
APT31
apt_group
Information theft and espionage
🇨🇳 CN
CL-STA-0043
apt_group
Information theft and espionage
🇨🇳 CN
Operation Diplomatic Specter
apt_group
Information theft and espionage
🇨🇳 CN
Mana Team
apt_group
🇨🇳 CN
SharpPanda
apt_group
Information theft and espionage
🇨🇳 CN
APT 5
apt_group
Information theft and espionage
🇨🇳 CN
Triage Info
Decided atMar 20, 2026