Fortra Releases New Updates for GoAnywhere: What HANDD Customers Need to Know
At HANDD, we’re always keeping a close eye on the latest developments from our technology partners, and this month, Fortra has rolled out a significant round of updates across the GoAnywhere product family, covering MFT, Agents, Gateway, and the Outlook Plugin. Below, we break down what’s new, what’s fixed, and what we recommend for your environment.
GoAnywhere MFT 7.10.1
The standout item in this release is Fortra’s renewed Drummond Certification for GoAnywhere MFT, reaffirming its compliance with industry interoperability standards — good news for organizations that rely on that certification as part of their vendor assurance process.
Other key enhancements include:
- New V2 RADIUS provider with Message Authenticator support, giving admins a more secure option for two-factor authentication and RADIUS login methods.
- Lucene Directory Type flag (Auto, NIO, or MMAP), offering more control over search indexing behavior, along with a smoother migration path from the legacy system property and better support for Windows UNC paths at startup.
- Agent Transfer performance options, including opt-in thread caching and thread pooling for faster transfers.
- Improved security controls across Web Client pages and REST APIs.
- A reworked approach to generating Job and File Audit IDs, guaranteeing uniqueness without relying on database or cluster resources (note: ID values will appear larger, but ordering is preserved).
On the fixes side, Fortra resolved a memory leak tied to queued transfer requests, a race condition affecting job cancellation during shutdown, and several SFTP/SSH issues — including a timestamp preservation bug and a proxy authentication failure in the Mina SSH provider. Clustered environments also benefit from a fix ensuring Active Transfers display activity across all nodes, not just the local one.
Underlying components have also been refreshed: Apache Tomcat (9.0.120), Netty (4.2.15), and the PostgreSQL JDBC driver (42.7.11), now verified with an automated connectivity smoke test.
GoAnywhere Agents 3.5.0
A notable security enhancement in this release: Agent executables are now digitally signed with a trusted code-signing certificate, strengthening trust and integrity verification across deployed agents.
Fortra has also made the client/server connection bridge optimization for reverse and forward proxying — previously opt-in — enabled by default, improving data transfer efficiency out of the box.
Additional updates include a fix for UDP back-pressure in Gateway that should meaningfully reduce packet loss, plus updates to the Azul Java 11 runtime (11.0.31) and log4j (2.25.4).
GoAnywhere Gateway 2.6.1
Gateway’s release centers on transfer setup performance, with an improved threading model that speeds up Agent transfer initialization.
It also carries over several fixes shared with MFT — including the SSH command timeout issue, the SFTP timestamp preservation fix, and the Mina SSH proxy authentication fix — along with the PostgreSQL JDBC driver upgrade and its new connectivity smoke test.
Outlook Plugin 3.3.1 — Security Update
This release is smaller in scope but important: Fortra has upgraded the log4net package from 2.0.15 to 3.3.2, resolving CVE-2026-40021. We strongly encourage all Outlook Plugin users to prioritize this update.
HANDD’s Recommendation
Given the security-relevant changes across this release cycle — the renewed Drummond Certification, RADIUS Message Authenticator support, tightened Web Client/REST API controls, digitally signed Agent executables, and the CVE-2026-40021 fix in the Outlook Plugin — we recommend planning your upgrade across your GoAnywhere estate as soon as practical.
As always, back up your environment before upgrading and review Fortra’s full release notes for any configuration details relevant to your setup.
If you’d like support planning or carrying out your upgrade, HANDD’s team is on hand to help — get in touch with us today.
Need more information or assistance? If you have any questions about these updates or require help with your GoAnywhere upgrade, please contact our support team at support@handd.co.uk.

















