Fortra Patches Critical Vulnerabilities in BoKS Privileged Access Manager (CVE-2026-79901, CVE-2026-79898, CVE-2026-12627)

Fortra Patches Critical Vulnerabilities in BoKS Privileged (TL-2026-2854) is a critical-severity software vulnerability scored CVSS 9.9, first published 2026-10-03. It has no confirmed attribution, affects Fortra Core Privileged Access Manager (BoKS) - BoKS Manager, references 3 CVEs (CVE-2026-79901, CVE-2026-79898, CVE-2026-12627), maps to 4 MITRE ATT&CK techniques (T1059.004, T1078.002, T1110.002), and is covered by 9 detection rules and 5 indicators of compromise.

Key facts for TL-2026-2854

Threat ID
TL-2026-2854
Severity
CRITICAL
CVSS
9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
Status
PATCHED
Category
VULNERABILITY
First published
2026-10-03
Last reviewed
2026-10-03
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, finance, government administration, telecoms, enterprise
Target regions
Global
Detection rules
9
Indicators of compromise
5

Malware and tooling in Fortra Patches Critical Vulnerabilities in BoKS Privileged

Malware and tooling: Fortra

Fortra patched three critical flaws in Core Privileged Access Manager (BoKS): predictable AD service-account password generation seeded by the Unix timestamp (CVSS 9.9), authenticated command injection in crlserver running as root (CVSS 9.1), and a remote unauthenticated stack buffer overflow in boks_autoregisterd (CVSS 9.8). Five further high/medium issues were also fixed. No in-the-wild exploitation was reported.

How Fortra Patches Critical Vulnerabilities in BoKS Privileged works

Fortra disclosed and patched multiple vulnerabilities in Core Privileged Access Manager (BoKS), the Unix/Linux privileged access and credential-vaulting platform. NVD published the three critical CVEs on 2026-10-01 (advisories FI-2026-012, FI-2026-015 and FI-2026-017) and SecurityWeek reported them on 2026-10-03. Because the BoKS Master is the trust anchor for privileged access across the managed Unix estate, compromise of the Master or of the service accounts it provisions has outsized blast radius.

CVE-2026-79901 (CVSS 9.9, CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, CWE-338, advisory FI-2026-012): in deployments using BoKS keytab management, boks_keytabmd generates Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. SecurityWeek classes this as an authentication bypass and states exploitation requires knowledge of the service principal and an estimate of when the password was changed; an attacker with those inputs can narrow the candidate password space to a small set of timestamp seeds. NVD lists boks-server as affected from 0 up to (excluding) 9.0.0.6, with 9.0.0.6 onward unaffected.

CVE-2026-79898 (CVSS 9.1, CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H, CWE-78, advisory FI-2026-015): crlserver processes shell command substitution supplied in a certificate revocation list (CRL) URL. An authenticated user authorized to add CRL URLs through the BoKS Control Center (BCC), the WSI REST or SOAP API, or the cacrl command-line interface can cause commands to run as root on the BoKS Master. Exposure through BCC and the WSI APIs means the attack is network-reachable and does not depend on local sudo/suexec rules. NVD lists BoKS Manager 8.1.0.0 through 8.1.0.23 and 9.0.0.0 through 9.0.0.6 as affected.

CVE-2026-12627 (CVSS 9.8, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, CWE-121, advisory FI-2026-017): a stack-based buffer overflow in boks_autoregisterd that remote, unauthenticated attackers with network access can trigger during client response processing, causing memory corruption. NVD lists BoKS 8.1.0.0 through 8.1.0.23 and 9.0.0.0 through 9.0.0.6 as affected.

Five additional high- and medium-severity flaws were fixed: two heap buffer overflows, an out-of-bounds read, insecure temporary file handling and a further predictable password generation issue. The sources do not give their CVE identifiers. SecurityWeek reports no exploitation in the wild and no public PoC is mentioned in any source; a lookup of the CISA KEV catalog did not surface these CVEs (the check was against a partial excerpt, so treat it as unconfirmed).

Context: this is not the first 2026 BoKS disclosure. Fortra advisory FI-2026-007 (identified 2026-05-27, disclosed 2026-06-15) covered CVE-2026-9862, an unauthenticated OS command injection (CVSS 9.8) in the same boks_autoregisterd service, and CVE-2026-9863, command injection in the legacy tar-based client upgrade tooling. Repeated critical findings in boks_autoregisterd mean that exposure of that service deserves priority regardless of patch level.

The Fortra advisory pages returned HTTP 403 to the collector, so fixed release numbers are not confirmed here; defenders should take them from the Fortra advisories. Because NVD marks 9.0.0.6 as affected for CVE-2026-79898 and CVE-2026-12627 but unaffected for CVE-2026-79901, the fixed release for those two must be later than 9.0.0.6.

MITRE ATT&CK techniques used in TL-2026-2854

Execution

T1059.004 Unix Shell

Persistence

T1078.002 Domain Accounts

Credential Access

T1110.002 Password Cracking

Initial Access

T1190 Exploit Public-Facing Application

Affected products and versions in Fortra Patches Critical Vulnerabilities in BoKS Privileged

  • Fortra — Core Privileged Access Manager (BoKS) - BoKS Manager
    Vulnerable versions: 8.1.0.0 through 8.1.0.23 (CVE-2026-79898, CVE-2026-12627); 9.0.0.0 through 9.0.0.6 (CVE-2026-79898, CVE-2026-12627); boks-server below 9.0.0.6 (CVE-2026-79901)
    Fixed in: boks-server 9.0.0.6 and later (CVE-2026-79901, per NVD); Other fixed releases: see Fortra advisories FI-2026-015 and FI-2026-017 (not stated in collected sources)

Remediation for Fortra Patches Critical Vulnerabilities in BoKS Privileged

Patches

  • Fortra BoKS fixed releases per advisories FI-2026-012, FI-2026-015 and FI-2026-017 (boks-server 9.0.0.6 and later is unaffected by CVE-2026-79901; fixed releases for the other two are not stated in the collected sources)

Immediate actions

  • Apply the Fortra patches referenced in advisories FI-2026-012, FI-2026-015 and FI-2026-017 to all BoKS Manager/Master and server hosts
  • Restrict who can add CRL URLs via BCC, the WSI REST/SOAP API and the cacrl CLI to a minimal set of trusted administrators
  • Limit network exposure of boks_autoregisterd and the BCC/WSI interfaces to trusted management networks

Workarounds

  • Rotate AD service-account passwords generated by boks_keytabmd once the patched version is deployed
  • Where keytab management is not required, avoid enabling it until patched

Longer-term hardening

  • Monitor the BoKS Master for crlserver spawning shells or unexpected child processes running as root
  • Alert on boks_autoregisterd crashes or abnormal client registration traffic
  • Review Kerberos/AD authentication activity for service accounts managed by BoKS keytab management

CVEs associated with Fortra Patches Critical Vulnerabilities in BoKS Privileged

CVE-2026-79901, CVE-2026-79898, CVE-2026-12627

Weaknesses (CWE) in Fortra Patches Critical Vulnerabilities in BoKS Privileged

CWE-338, CWE-78, CWE-121

Timeline of Fortra Patches Critical Vulnerabilities in BoKS Privileged

  • Context: Fortra identifies the earlier BoKS issue later disclosed as FI-2026-007 (CVE-2026-9862, command injection in boks_autoregisterd); a separate advisory from the three flaws in this record.
  • Context: Fortra publicly discloses FI-2026-007 covering CVE-2026-9862 (unauthenticated command injection, CVSS 9.8) and CVE-2026-9863 (legacy tar client upgrade command injection) in BoKS.
  • NVD records for CVE-2026-79901 and CVE-2026-79898 are modified within hours of publication (79898 last modified 20:34 UTC), refining affected-version data.
  • Fortra patches the three critical flaws plus five additional high/medium issues (two heap buffer overflows, an out-of-bounds read, insecure temporary file handling, predictable password generation) in BoKS.
  • Fortra advisory FI-2026-017 and NVD publish CVE-2026-12627 (CVSS 9.8): unauthenticated stack-based buffer overflow in boks_autoregisterd.
  • Fortra advisory FI-2026-015 and NVD publish CVE-2026-79898 (CVSS 9.1, 15:17 UTC): crlserver command injection executing as root on the BoKS Master via BCC, WSI REST/SOAP or cacrl.
  • Fortra advisory FI-2026-012 and NVD publish CVE-2026-79901 (CVSS 9.9, 14:17 UTC): predictable, Unix-timestamp-seeded AD service-account password generation in boks_keytabmd; boks-server 9.0.0.6 onward unaffected.
  • SecurityWeek reports the Fortra BoKS patches and notes no in-the-wild exploitation has been reported.

Sources cited for Fortra Patches Critical Vulnerabilities in BoKS Privileged

More in vulnerability

Detection coverage for TL-2026-2854

As of 2026-10-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2854 across Splunk SPL, Microsoft KQL and Sigma, covering 5 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats