In this blog post, I’ll share the story of how I discovered CVE-2026-9177, a critical Server-Side Template Injection (SSTI) vulnerability in one of the most popular Managed File Transfer (MFT) gateways, Axway SecureTransport.
Axway SecureTransport is a Managed File Transfer Gateway that enables file sharing across business networks. The platform is used across critical sectors, including aviation, healthcare, and finance.
The vulnerability I found enabled a complete takeover of the underlying hosting infrastructure through remote code execution. It’s a good reminder that even widely used, mature tools can hide serious flaws, and that security requires continuous effort. Regular security research, like penetration testing, is what uncovers these hidden issues. As ethical hackers, we have an important role to play here: finding these flaws and reporting them to vendors so they can be patched before attackers find them first.