Vulnerabilities & Exploits

Fortra BoKS Patch Fixes Six Privileged Access Flaws

Fortra published patches for six vulnerabilities in Core Privileged Access Manager (BoKS), including three critical flaws, affecting versions 8.1.0.0 through 8.1.0.23 and 9.0.0.0 through 9.0.0.6. The fixed releases are 8.1.0.24 and later, and 9.0.0.7 and later.

One bug lets a remote unauthenticated attacker hit boks_autoregisterd and corrupt memory; another lets an authenticated user turn a URL field in crlserver into root on the BoKS master. CVE-2026-79901 is the quieter trap: BoKS can generate predictable Active Directory service-account passwords from keytab-managed accounts, so someone who knows the service name and rough change time can guess credentials offline.

That makes the blast radius bigger than the appliance itself. If BoKS manages Active Directory identities in your environment, exposure can reach the downstream accounts those keytabs protect, and the registration service on port 6507 increases pre-patch risk wherever it is reachable.

2 sources · 4h ago

CVE-2026-79901

NVD KEV

CVSS 9.9 CRITICAL: in deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory…

CVE-2026-12627

NVD KEV

CVSS 9.8 CRITICAL: fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow vulnerability in boks_autoregisterd.

CVE-2026-79898

NVD KEV

CVSS 9.1 CRITICAL: fortra BoKS Manager contains a command injection vulnerability in crlserver.

Timeline

Sources

Part of the PlainSec briefing for 2026-10-02

Every edition of this story: Fortra BoKS Patch Fixes Six Privileged Access Flaws

More from today