Top 6 Managed File Transfer and Secure File Sharing Tools for 2026: Compared on Patch Record
GoAnywhere, MOVEit, Cleo, Kiteworks, Boomi MFT, and AWS Transfer Family, with the exploitation history every other comparison leaves out.
The short answer
Managed file transfer is the only software category whose public profile was built by getting breached. Every serious comparison should therefore start with the patch record, and almost none of them do. This one does.
- Fortra GoAnywhere MFT for large hybrid partner networks that need on-premises control, deployed with the admin console off the internet.
- Progress MOVEit for regulated transfers needing deep audit evidence, and prefer MOVEit Cloud unless residency forces self-hosting.
- Kiteworks for sensitive data with residency requirements and a small user population. The only vendor here with a published entry price: $25.50 per user per month.
- Cleo when file transfer and EDI are genuinely the same workflow, and after you have asked about the December 2024 incomplete patch.
- Boomi MFT if you already run Boomi. It is no longer sold standalone.
- AWS Transfer Family if you control both ends and want fully published pricing: $0.30 per protocol hour, $0.04 per GB.
- None of them if you are moving files between two systems you own. That is SFTP plus a scheduler, not a licence.
Last verified: September 2026.
Make patch and disclosure speed an explicit criterion
This is the information gain on this page. Nobody else scores it, and it is the variable that has actually decided outcomes in this category.
Ask every vendor these five questions and record the written answers next to the feature matrix:
- Is there a dated, numbered advisory feed for this product, covering at least two years? Fortra publishes numbered advisories (the GoAnywhere deserialization flaw is FI-2025-012). Progress publishes per-product security alert bulletins on its community site and runs a public trust center. Cleo publishes security update articles in its support knowledge base. A vendor that cannot point you at a feed has already answered the question.
- How many days elapsed between internal discovery and customer advisory for the last three critical issues? Ask for the number, not a policy statement.
- Does the advisory state whether exploitation was observed before the patch shipped? This one separates vendors who prioritize your incident response from vendors who prioritize their own reputation. Fortra's GoAnywhere advisory carried a discovery date of 11 September 2025 while public disclosure followed later that month, and independent researchers established exploitation in that window.
- How are affected customers contacted directly? Email to named security contacts, in-product notice, and account team outreach, or a web page you are expected to check.
- What happened the last time a fix turned out to be incomplete? Cleo is the case study, and it is the worst failure mode in the category, because it converts a diligent customer's correct action into false assurance.
The record, with dates
Every entry below is drawn from vendor advisories or government agency advisories, not from news summaries.
Accellion FTA, December 2020. Zero-day exploitation of the legacy File Transfer Appliance hit government and private organizations internationally. Accellion rebranded to Kiteworks in October 2021 and states the flaws were confirmed only in FTA, which ran a separate codebase from the Kiteworks platform. Accellion settled related healthcare litigation for $8.1 million.
GoAnywhere MFT, February 2023. CVE-2023-0669, remote code execution. CISA advisory AA23-158A records the Cl0p group claiming data exfiltrated from approximately 130 victims over ten days.
MOVEit Transfer, May 2023. CVE-2023-34362, SQL injection. The same CISA advisory states Cl0p began exploiting it on 27 May 2023, installing the LEMURLOOT web shell to steal data from MOVEit Transfer databases. This became the defining supply chain data-theft campaign of the period.
MOVEit Transfer, June 2024. CVE-2024-5806, an authentication bypass in the SFTP module, disclosed with a Progress security bulletin and flagged by CISA.
Cleo Harmony, VLTrader, and LexiCom, December 2024. CVE-2024-50623 was patched in version 5.8.0.21 in October 2024. In December, active exploitation bypassing that patch was identified, and a second flaw, CVE-2024-55956, was fixed in 5.8.0.24. Both entered CISA's Known Exploited Vulnerabilities catalog and Cl0p claimed the campaign.
GoAnywhere MFT, September 2025. CVE-2025-10035, a deserialization flaw in the License Servlet with a CVSS score of 10.0, covered by Fortra advisory FI-2025-012 with a stated discovery date of 11 September 2025. It was exploited as a zero-day before public disclosure, added to CISA's Known Exploited Vulnerabilities catalog, and linked to Medusa ransomware deployment. Fixed in 7.8.4 and the 7.6.3 sustain release.
MOVEit Automation, April 2026. Progress disclosed CVE-2026-4670, an authentication bypass scored CVSS 9.8, chained with CVE-2026-5174 for privilege escalation, on 30 April 2026. Fixed in 2025.1.5, 2025.0.9, and 2024.1.8. No workaround exists and remediation requires a full-installer upgrade, which means planned downtime.
What the pattern actually tells you
Read across those events and one thing is constant. In every case the exploited component was internet-reachable and customer-operated. The extortion groups are not finding exotic memory corruption bugs; they are finding authentication bypasses and deserialization flaws in admin consoles and service endpoints that were exposed to the whole internet because that was the easiest way to deploy.
Three consequences for how you buy:
- Network placement beats product choice. The admin console belongs on a private network segment. Partner-facing protocols belong in a DMZ proxy tier, not on the application server. That architecture would have blunted most of the events above regardless of vendor.
- Patch capability is a purchase criterion about you, not the vendor. If your change process cannot ship an emergency patch to an internet-facing application within 48 hours, self-hosted MFT is the wrong choice. A vendor-managed cloud option is the honest one.
- A clean record is not proof of safety. Boomi MFT and AWS Transfer Family have no public mass-exploitation event, which is genuinely worth something, and it partly reflects architecture (no customer-operated appliance) and partly reflects smaller installed bases. Do not read it as a guarantee.
Who is still an independent purchase
This market consolidated while nobody was watching, and a lot of comparison content has not caught up.
Thru no longer exists as a vendor. Boomi announced its acquisition on 15 May 2025, and the technology is now Boomi Managed File Transfer inside the Boomi Enterprise Platform. The thruinc.com domain redirects to Boomi. If a comparison still lists Thru as an independent option, it was written from stale data. For a buyer with no Boomi footprint, this means evaluating an entire enterprise integration platform to obtain file transfer, which is rarely the right trade.
Kiteworks is Accellion renamed, since October 2021. That is not a criticism, and the FTA codebase distinction the company draws is technically real. It still belongs in your evaluation, because the organizational question does not transfer to a new brand: how the vendor behaved during an incident, and what changed afterwards.
The rest (Fortra, Progress, Cleo, AWS) remain straightforwardly purchasable as of September 2026.
The cloud-native alternative, honestly
AWS Transfer Family is the option most buyers should price out before signing an MFT licence, and the option most of them will correctly reject.
What you get: managed SFTP, FTPS, FTP, and AS2 endpoints in front of Amazon S3 or EFS. Identity comes through IAM or your directory, and logging through CloudWatch. Published rates for US East (N. Virginia) are $0.30 per protocol hour and $0.04 per GB for SFTP, FTPS, and FTP. AS2 is $0.01 per message up to 50 MB for the first 100,000 monthly messages. Web app units cost $0.50 per hour for 250 concurrent sessions, and PGP decrypt workflows $0.10 per GB.
What you do not get: trading-partner onboarding, partner credential self-service, EDI translation, retry and escalation workflow, packaged non-repudiation reporting, or an operations console anyone outside engineering can use. Azure and Google Cloud have comparable gaps in their equivalents.
The decision rule is simple. If you control both ends, or your partners are few and technical, the cloud service is cheaper, more transparent, and has no appliance for you to misconfigure. If you onboard hundreds of external partners with varied protocol demands and somebody in operations needs a console, you are buying an MFT product whether you want to or not.
Where this sits in the rest of the stack
Managed file transfer is one control in a data protection story, not the whole of it.
- The data loss prevention tools comparison covers classifying and stopping the data before it reaches a transfer channel.
- The secure email providers comparison covers the person-to-person channel that MFT is frequently, and wrongly, bought to replace.
- The vulnerability management platform comparison covers knowing you are running the affected version on the day the advisory lands, which is the difference between a 48-hour patch and a breach notification.
- The ransomware backup and recovery comparison covers what happens after, since Medusa ransomware deployment followed the September 2025 GoAnywhere exploitation.
- The external attack surface management comparison covers finding the MFT admin console somebody exposed to the internet three years ago and forgot.
Who should not buy this category
- Internal-only file movement. Two systems you own, inside one network boundary: use SFTP with key-based authentication, a scheduler, and monitoring. MFT adds licence cost, administrative weight, and an internet-facing attack surface for governance features you will never invoke.
- Occasional person-to-person document sharing. If the requirement came from legal or finance needing to send sensitive documents to outside counsel, that is secure file sharing. Your existing collaboration suite with data loss prevention, or a governed sharing product, is cheaper and less exposed.
- Organizations that cannot patch an internet-facing application within days. Every event documented above punished exactly that. If the staffing is not there, do not buy a self-hosted appliance. Buy a vendor-managed service and make patching someone else's contractual obligation.
Quick Comparison
| Product | Best for | Deployment | Published price | Mass-exploitation history |
|---|---|---|---|---|
| Fortra GoAnywhere MFT | Large on-premises and hybrid partner networks | On premises, private cloud, hosted | No, quote only by module and instance | Yes: CVE-2023-0669 (Feb 2023) and CVE-2025-10035 (Sep 2025) |
| Progress MOVEit Transfer | Enterprises needing broad protocol and compliance coverage | On premises or MOVEit Cloud | No, quote only | Yes: CVE-2023-34362 (May 2023); further criticals in 2024 and 2026 |
| Kiteworks | Regulated data with strict governance and residency needs | Hardened appliance, private or hosted cloud | Yes, Business edition $25.50 per user per month | Predecessor product: Accellion FTA zero-days (Dec 2020) |
| Cleo | EDI and supply chain integration alongside file transfer | On premises or Cleo-hosted | No, quote only | Yes: CVE-2024-50623 and CVE-2024-55956 (Dec 2024) |
| Boomi MFT (formerly Thru) | Teams already standardized on the Boomi platform | Cloud native, inside Boomi | No, quote only | No public mass-exploitation event |
| AWS Transfer Family | Protocol endpoints in front of S3 with no vendor appliance | AWS managed service | Yes, fully published per hour and per GB | No public mass-exploitation event |
Fortra GoAnywhere MFT
- Best for
- Large on-premises and hybrid partner networks
- Deployment
- On premises, private cloud, hosted
- Published price
- No, quote only by module and instance
- Mass-exploitation history
- Yes: CVE-2023-0669 (Feb 2023) and CVE-2025-10035 (Sep 2025)
Progress MOVEit Transfer
- Best for
- Enterprises needing broad protocol and compliance coverage
- Deployment
- On premises or MOVEit Cloud
- Published price
- No, quote only
- Mass-exploitation history
- Yes: CVE-2023-34362 (May 2023); further criticals in 2024 and 2026
Kiteworks
- Best for
- Regulated data with strict governance and residency needs
- Deployment
- Hardened appliance, private or hosted cloud
- Published price
- Yes, Business edition $25.50 per user per month
- Mass-exploitation history
- Predecessor product: Accellion FTA zero-days (Dec 2020)
Cleo
- Best for
- EDI and supply chain integration alongside file transfer
- Deployment
- On premises or Cleo-hosted
- Published price
- No, quote only
- Mass-exploitation history
- Yes: CVE-2024-50623 and CVE-2024-55956 (Dec 2024)
Boomi MFT (formerly Thru)
- Best for
- Teams already standardized on the Boomi platform
- Deployment
- Cloud native, inside Boomi
- Published price
- No, quote only
- Mass-exploitation history
- No public mass-exploitation event
AWS Transfer Family
- Best for
- Protocol endpoints in front of S3 with no vendor appliance
- Deployment
- AWS managed service
- Published price
- Yes, fully published per hour and per GB
- Mass-exploitation history
- No public mass-exploitation event
Fortra GoAnywhere MFT
Best for EnterpriseBest for: Large hybrid partner networks that need deep protocol coverage and on-premises control
“GoAnywhere is the most capable general-purpose MFT product here for a complex partner network: broad protocol support, strong workflow automation, granular key and certificate handling, and deployment models that keep data on your infrastructure. It has also been mass-exploited twice, in February 2023 and again in September 2025, and any honest recommendation has to carry that. The security question with GoAnywhere is not whether it can be operated safely, it is whether your team will keep the admin console off the public internet and patch on the day an advisory lands.”
Pros
- Deep protocol and workflow coverage: SFTP, FTPS, AS2, AS4, HTTPS, PGP, plus scheduling and translation steps
- Deployment flexibility across on premises, private cloud, and hosted, which suits data residency and air-gapped requirements
- Modular licensing means you can start with core transfer and add Secure Mail or GoDrive later
- Fortra publishes numbered product security advisories with dates, which makes its patch history auditable rather than anecdotal
Cons
- Two separate mass-exploitation events in under three years, both against internet-exposed components
- No published pricing, and module-plus-instance licensing makes quotes hard to compare against competitors
- Feature depth carries administrative weight; this is not a product you run without an owner
Security track record
CVE-2023-0669, remote code execution, exploited by Cl0p from late January 2023; CISA advisory AA23-158A records the group claiming approximately 130 victims in ten days. CVE-2025-10035 was a CVSS 10.0 deserialization flaw in the License Servlet, covered by Fortra advisory FI-2025-012 with a stated discovery date of 11 September 2025. It was exploited as a zero-day before disclosure and subsequently added to CISA KEV. Fixed releases were 7.8.4 and the 7.6.3 sustain release.
What to ask the vendor
Ask for the mean time from internal discovery to customer advisory across the last three critical CVEs. Ask how customers are notified outside the advisory page. Ask what the supported upgrade path looks like when an advisory says patch today.
Deployment guidance
Put the admin console behind a VPN or a private network segment with no internet route. Terminate partner-facing protocols in a DMZ proxy tier rather than exposing the application server. Both mass-exploitation events would have been substantially blunted by that architecture.
No published price. Fortra licenses GoAnywhere MFT by module or server component per instance, with Secure Mail and GoDrive priced per user, quoted on request.
Progress MOVEit Transfer
Runner UpBest for: Enterprises that need broad protocol coverage, compliance reporting, and a managed cloud option
“MOVEit is the most widely recognized name in managed file transfer and a genuinely strong product: comprehensive audit trails, mature compliance reporting, a hosted MOVEit Cloud option, and an automation tier for scheduled workflows. It is also the product whose 2023 breach became the defining supply chain data-theft event of the decade, and it has shipped further critical vulnerabilities since. What matters for a 2026 buyer is not that MOVEit had a bad year, it is how the vendor has handled every disclosure cycle since, and that record is mixed.”
Pros
- Strongest audit and compliance reporting in the category, which shortens evidence gathering for regulated transfers
- MOVEit Cloud removes appliance patching from your team, which directly addresses the failure mode that caused the 2023 losses
- Broad protocol and integration coverage including cloud storage targets
- Progress publishes dated security alert bulletins per product and runs a public trust center
Cons
- Three separate critical disclosure cycles since 2023, the most recent in April 2026
- Remediation for the 2026 Automation flaws required a full-installer upgrade with no workaround, meaning planned downtime
- No published pricing; quote only, with a 30-day trial as the only self-serve entry
Security track record
CVE-2023-34362, SQL injection in MOVEit Transfer, exploited by Cl0p from 27 May 2023, documented in CISA advisory AA23-158A alongside the LEMURLOOT web shell. CVE-2024-5806, SFTP authentication bypass, June 2024. CVE-2026-4670 (CVSS 9.8 authentication bypass) and CVE-2026-5174 (privilege escalation) in MOVEit Automation, disclosed 30 April 2026, fixed in 2025.1.5, 2025.0.9, and 2024.1.8, with no workaround available.
What to ask the vendor
Ask how MOVEit Cloud customers were protected during each of those cycles relative to self-hosted customers, with dates. That single answer is the clearest available evidence on whether the managed option is worth the premium.
Deployment guidance
If you self-host, budget a standing maintenance window you can invoke within 48 hours, because the 2026 fix required a full installer and a service outage. If you cannot commit to that, MOVEit Cloud is the more honest choice.
No published price. Progress quotes MOVEit on request through its sales team; a 30-day trial is available.
Kiteworks
Best ValueBest for: Regulated data exchange where governance, residency, and audit evidence outrank raw protocol breadth
“Kiteworks is built around governance rather than transfer mechanics: a hardened appliance, consolidated policy across secure email, file sharing, and transfer, selectable hosting regions, and the audit evidence a privacy regulator asks for. It is also the only vendor in this comparison that publishes a real entry price, at $25.50 per user per month for the Business edition with a stated 40% discount for annual billing. The history you need to know is that Kiteworks is Accellion renamed, and the Accellion File Transfer Appliance was one of the original mass-exploitation events in this category.”
Pros
- Published, self-serve Business edition pricing at $25.50 per user per month, in a category that otherwise hides every number
- Selectable hosting regions across the Americas, Europe, and Asia Pacific, which makes data residency commitments straightforward
- Governance model spans secure email, file sharing, and transfer under one policy and one audit log
- Hardened virtual appliance architecture narrows the exposed surface compared with a general application server
Cons
- Business edition caps are restrictive: 5 to 100 users, 2 GB maximum file size, 1 TB storage, 50 GB per month bandwidth
- Enterprise edition is call-for-pricing with no published figure
- Lighter than GoAnywhere or Cleo on classic B2B protocol automation such as AS2 trading-partner workflows
Security track record
The predecessor product, Accellion FTA, was exploited through zero-day vulnerabilities from December 2020 in a campaign affecting government and private sector organizations internationally. Accellion rebranded as Kiteworks in October 2021 and states that the vulnerabilities were confirmed only in FTA, which ran a separate codebase from the Kiteworks platform.
Edition limits
Business: 5 to 500 users per the pricing page, with the online store selling 5 to 100 users, 2 GB maximum file size, 1 TB storage, 50 GB per month bandwidth, hosted cloud with a selectable region. Enterprise: unlimited users and a stated 16 TB maximum file size, call for pricing.
What to ask the vendor
Ask for the current coordinated disclosure policy, the notification channel and timeline customers can expect, and the most recent product security advisories with dates. A vendor with this history should be able to answer all three immediately.
Published for the Business edition: $25.50 per user per month, with a stated 40% discount for annual billing, sold for 5 to 100 users through the online store. Enterprise edition is call for pricing.
Cleo
Honorable MentionBest for: Supply chain and EDI integration where file transfer and trading-partner workflow are one problem
“Cleo is a different shape of product from the rest of this list. Harmony, VLTrader, and LexiCom sit where file transfer meets EDI and B2B integration, which is why Cleo is entrenched in logistics, manufacturing, and food distribution. If your file movement is inseparable from trading-partner onboarding and document translation, Cleo does something the general-purpose MFT products do not. Its December 2024 exploitation episode also produced the single worst disclosure data point in this comparison, and it deserves to be weighed heavily.”
Pros
- Combines managed file transfer with EDI and B2B integration, removing a whole category of middleware for supply chain operations
- Deep trading-partner onboarding, document translation, and protocol handling for logistics and manufacturing workflows
- Entrenched ecosystem knowledge in verticals where partner requirements are idiosyncratic
- Publishes product security update articles in its public support knowledge base
Cons
- The October 2024 patch for CVE-2024-50623 proved bypassable and the flaw was mass-exploited in December 2024
- Two CVEs in the same component chain landed in CISA's Known Exploited Vulnerabilities catalog within days of each other
- No published pricing; quote only
Security track record
CVE-2024-50623 disclosed and patched in 5.8.0.21 in October 2024; active exploitation bypassing that patch identified in December 2024. CVE-2024-55956, arbitrary command execution via Autorun directory defaults, fixed in 5.8.0.24. Both added to CISA's Known Exploited Vulnerabilities catalog in December 2024, with Cl0p claiming responsibility for the data theft campaign.
What to ask the vendor
Ask what changed in patch verification after the 5.8.0.21 bypass. Ask whether the vendor now publishes a statement of whether exploitation was observed at the time of each advisory. Ask how customers running an affected version are contacted directly rather than expected to read the knowledge base.
Deployment guidance
The Autorun directory default that enabled CVE-2024-55956 is a reminder to audit default configurations rather than trusting them. Review the hardening guide line by line at install, and re-review it after every major upgrade.
No published price. Cleo quotes Harmony, VLTrader, LexiCom, and its integration cloud on request.
Boomi MFT (formerly Thru)
FastestBest for: Organizations already standardized on the Boomi integration platform
“Thru was a credible cloud-native MFT vendor with no public mass-exploitation history, which in this category is a genuine distinction. It is also no longer an independent purchase. Boomi announced the acquisition on 15 May 2025 and has folded the technology into its platform as Boomi Managed File Transfer; the thruinc.com domain now redirects to Boomi. That makes it an excellent option for existing Boomi customers and a poor shortlist entry for anyone else, because you would be buying an integration platform to get a file transfer product.”
Pros
- Cloud-native, multi-tenant architecture with no customer-managed appliance to patch, which removes the failure mode behind most incidents on this page
- No public mass-exploitation event in its history
- File movement sits alongside API and application integration in one platform, with one set of monitoring and credentials
- Removes the DMZ proxy tier and certificate estate that on-premises MFT requires
Cons
- No longer sold standalone; it is a capability of the Boomi Enterprise Platform since the May 2025 acquisition
- No published pricing, and the commercial conversation is a platform conversation
- Product roadmap now serves Boomi's integration strategy rather than MFT buyers specifically
Acquisition status
Boomi announced the acquisition of Thru, Inc. on 15 May 2025, describing it as an expansion of file-based integration within the Boomi Enterprise Platform. The former thruinc.com URLs now redirect to Boomi's managed file transfer platform pages.
Why the architecture matters
Every mass-exploitation event on this page involved a customer-operated, internet-reachable component. A multi-tenant service where the vendor patches shifts that risk, though it concentrates it: a flaw in the service affects every tenant at once, and you have no ability to patch faster than the provider.
What to ask the vendor
Ask for the managed file transfer release notes since May 2025 and for the security advisory channel that covers this specific capability rather than the platform generally.
No published price. Sold as part of the Boomi Enterprise Platform, quoted on request, historically priced by data volume.
AWS Transfer Family
Best Free OptionBest for: Teams that need SFTP, FTPS, FTP, or AS2 endpoints in front of their own storage without buying an MFT product
“AWS Transfer Family is the honest cloud-native alternative, and the only product in this comparison with fully published pricing. In US East (N. Virginia) that is $0.30 per protocol hour per enabled endpoint, $0.04 per GB for SFTP, FTPS, and FTP transfer, and per-message AS2 rates. It is not an MFT product and does not pretend to be. It gives you managed protocol endpoints in front of Amazon S3 or EFS, with IAM and CloudWatch doing the identity and audit work, and you build the rest. For a large share of buyers, that is what they actually needed.”
Pros
- Fully published pricing with no sales cycle: $0.30 per protocol hour, $0.04 per GB for SFTP, FTPS, and FTP, AS2 at $0.01 per message up to 50 MB for the first 100,000 monthly messages
- No appliance, no patching, and no internet-exposed admin console of your own to misconfigure
- Identity, authorization, logging, and encryption inherit from IAM, CloudWatch, and S3 rather than a vendor's implementation
- Managed workflows cover common needs such as PGP decryption, billed at $0.10 per GB
Cons
- No trading-partner community management, no partner self-service onboarding, no EDI translation
- Cost is usage-based and can exceed a licence for high-volume steady transfer, since endpoint hours accrue whether or not files move
- You own the workflow, alerting, and non-repudiation design that a commercial MFT product ships out of the box
What you get
Managed SFTP, FTPS, FTP, and AS2 endpoints that read and write directly to Amazon S3 or Amazon EFS, with authentication through AWS-managed users, a custom identity provider, or Active Directory, and logging through CloudWatch.
What you build
Partner onboarding and credential lifecycle, transfer success and failure alerting, retry and escalation logic, retention and legal hold policy, and any non-repudiation evidence your auditors expect. Budget engineering time for these explicitly.
Cost modelling
Endpoint hours accrue continuously per enabled protocol, so three protocols on one endpoint cost roughly $0.90 per hour before any bytes move. Model a full month of your real traffic profile, including idle hours, before comparing against a licence quote.
Published. $0.30 per protocol hour per enabled protocol. $0.04 per GB uploaded or downloaded for SFTP, FTPS, and FTP. AS2 is $0.01 per message up to 50 MB for the first 100,000 messages per month, then $0.005. SFTP connectors cost $0.001 per call plus $0.40 per GB. Web apps are $0.50 per hour per unit supporting up to 250 concurrent sessions, and PGP decrypt workflows $0.10 per GB. Rates shown for US East (N. Virginia); associated S3, EFS, Lambda, and CloudWatch charges are additional.
Which One Should You Pick?
| Use Case | Our Recommendation |
|---|---|
| Hundreds of external partners, mixed protocols, on-premises control required | Fortra GoAnywhere MFT, deployed with the admin console on a private network and partner protocols terminated in a DMZ proxy tier. |
| Regulated transfers where audit evidence and compliance reporting decide the purchase | Progress MOVEit, and strongly consider MOVEit Cloud so that patching the 2023 and 2026 class of flaws is the vendor's job rather than yours. |
| Sensitive data with residency requirements and a small user population | Kiteworks. Business edition at $25.50 per user per month with a selectable hosting region is the only published entry price in the category. |
| Logistics or manufacturing where file transfer and EDI are the same workflow | Cleo, after interrogating what changed in patch verification following the December 2024 incomplete-fix episode. |
| Already running Boomi for application and API integration | Boomi MFT. Adding file transfer inside the platform you already operate avoids a second vendor, a second audit, and a second credential estate. |
| Engineering team that controls both ends and wants predictable published costs | AWS Transfer Family. Protocol endpoints in front of S3 at published rates, with the partner management layer built yourself. |
| Moving files between two systems you own, inside one organization | None of these. SFTP with key-based authentication plus a scheduler and monitoring does this. MFT earns its price on external partners, non-repudiation, and audit, none of which apply here. |
How we evaluated
Last verified: September 2026.
Most managed file transfer comparisons score protocol checkboxes. Protocol support is table stakes across this shortlist, and it has never been the variable that decided an outcome. These are the dimensions used here:
- Security track record, with dates. Documented mass-exploitation events, the CVE identifiers, the fixed versions, and whether exploitation preceded disclosure. Every claim carries a date so it can be checked and so it ages visibly.
- Patch and disclosure behaviour. Whether the vendor publishes a dated advisory feed, whether advisories state observed exploitation, and what happened when a fix proved incomplete.
- Deployment model and who patches. Customer-operated appliance, vendor-managed cloud, or a managed service with no appliance at all. This determines which of the documented failure modes you inherit.
- Pricing transparency. Whether a real number exists on a vendor page, and what it covers.
- Corporate status. Whether the product is still an independent purchase, since this market consolidated during 2025.
What we checked
Product and pricing claims come from vendor pages read in September 2026. Exploitation claims come from vendor security advisories or from government agency advisories, never from a news summary or another comparison site.
- Kiteworks pricing page and its Business package store listing for the $25.50 per user per month figure, the stated 40% annual-billing discount, and the 5 to 100 user store range. The same pages give the 2 GB file size cap, 1 TB storage, 50 GB monthly bandwidth, and selectable hosting regions. They also state the Enterprise edition's call-for-pricing status, with unlimited users and a 16 TB file size ceiling.
- AWS Transfer Family pricing for every published rate quoted on this page, taken at US East (N. Virginia).
- Fortra's GoAnywhere pricing page for the licensing model (by module or server component per instance, with Secure Mail and GoDrive priced per user) and to confirm no figures are published.
- Progress MOVEit for product structure and to confirm pricing is quote-only with a 30-day trial.
- Boomi's managed file transfer platform page and the acquisition announcement dated 15 May 2025. We separately confirmed that thruinc.com now redirects into Boomi's platform pages, which is why Thru is listed here under its current name.
For the exploitation history:
- CISA advisory AA23-158A for CVE-2023-34362 in MOVEit Transfer, the 27 May 2023 start of Cl0p exploitation, and the LEMURLOOT web shell. The same advisory states that this group claimed data from approximately 130 GoAnywhere victims over ten days following CVE-2023-0669.
- Fortra advisory FI-2025-012 for CVE-2025-10035, its CVSS 10.0 rating, the 11 September 2025 discovery date, and the fixed releases 7.8.4 and 7.6.3.
- Cleo's own product security update article for CVE-2024-55956 and the 5.8.0.24 fix, alongside the October 2024 5.8.0.21 patch for CVE-2024-50623 that was subsequently bypassed in December 2024.
- Progress's MOVEit Automation critical security alert bulletin for April 2026 for CVE-2026-4670 and CVE-2026-5174, the 30 April 2026 disclosure, the fixed versions, and the absence of a workaround.
What we could not verify
Several vendor sites block automated retrieval. Fortra's pricing and advisory pages, Cleo's support knowledge base, and Progress's community advisory all return access errors to a crawler. Details from those sources were confirmed through their indexed content and cross-checked against the government advisories above, rather than read directly end to end. The CVE identifiers, CVSS scores, dates, and fixed version numbers are consistent across those sources. Confirm the current fixed versions on the vendor advisory itself before you plan an upgrade, because sustain-release version numbers change.
CISA Known Exploited Vulnerabilities catalog inclusion is stated here for CVE-2023-0669, CVE-2024-50623, CVE-2024-55956, and CVE-2025-10035 based on the corresponding agency and vendor advisories. Check the live catalog for current entries and due dates if you are using this for compliance purposes.
We found no published price for GoAnywhere, MOVEit, Cleo, or Boomi MFT, and we did not substitute an aggregator estimate for any of them. Specific dollar ranges circulate widely for these products and none of them is a vendor commitment.
What we did not do
We did not run these products, and this page makes no hands-on testing claims. Rankings reflect documented capability, published pricing, deployment model, corporate status, and the dated public security record.
We did not use the absence of a public exploitation event as evidence of superior engineering. Boomi MFT and AWS Transfer Family have no such event, which partly reflects architecture and partly reflects installed base and attacker attention. It is a real advantage and it is not a guarantee.
We did not rank vendors down for having disclosed vulnerabilities. Every product of this complexity has them. What is scored here is how fast the vendor moved, how clearly it told customers, and what it did when a fix was incomplete.
Editorial independence: this is a vendor-neutral comparison with no paid placements, sponsorships, or affiliate links. Rankings reflect fit for the stated use cases, not commercial relationships. Verify current licensing, current patch levels, and current supported versions directly with each vendor before you buy or upgrade.
Frequently Asked Questions
Why does managed file transfer software keep getting mass-exploited?
How should I evaluate a vendor's patch and disclosure speed?
Which managed file transfer vendors publish a price?
Is MOVEit safe to buy after the 2023 breach?
What is the difference between managed file transfer and secure file sharing?
Who should not buy managed file transfer software at all?
Does moving to a cloud-hosted MFT service remove the risk?
Related Comparisons
Security Control Validation
Top 5 Breach and Attack Simulation Tools for 2026: Cymulate vs SafeBreach vs Picus vs AttackIQ vs Pentera
5 tools compared
Secure Design and Threat Modeling
Top 5 Threat Modeling Tools for 2026: IriusRisk vs SD Elements vs ThreatModeler vs Threat Dragon vs Microsoft TMT
5 tools compared
Application Security Testing
Top 5 Intercepting Proxy Tools for 2026: Burp Suite vs mitmproxy vs ZAP vs Proxyman vs Charles
5 tools compared
Insider Threat Management
Top 5 Insider Threat Management (ITM) Tools of 2026: DTEX vs Proofpoint vs the Rest
5 tools compared