Fortra Patches Critical Vulnerabilities in BoKS Privileged Access Manager (CVE-2026-79901, CVE-2026-79898, CVE-2026-12627)
Fortra Patches Critical Vulnerabilities in BoKS Privileged (TL-2026-2854) is a critical-severity software vulnerability scored CVSS 9.9, first published 2026-10-03. It has no confirmed attribution, affects Fortra Core Privileged Access Manager (BoKS) - BoKS Manager, references 3 CVEs (CVE-2026-79901, CVE-2026-79898, CVE-2026-12627), maps to 4 MITRE ATT&CK techniques (T1059.004, T1078.002, T1110.002), and is covered by 9 detection rules and 5 indicators of compromise.
Key facts for TL-2026-2854
- Threat ID
- TL-2026-2854
- Severity
- CRITICAL
- CVSS
- 9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- 2026-10-03
- Last reviewed
- 2026-10-03
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, finance, government administration, telecoms, enterprise
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 5
Malware and tooling in Fortra Patches Critical Vulnerabilities in BoKS Privileged
Malware and tooling: Fortra
Fortra patched three critical flaws in Core Privileged Access Manager (BoKS): predictable AD service-account password generation seeded by the Unix timestamp (CVSS 9.9), authenticated command injection in crlserver running as root (CVSS 9.1), and a remote unauthenticated stack buffer overflow in boks_autoregisterd (CVSS 9.8). Five further high/medium issues were also fixed. No in-the-wild exploitation was reported.
How Fortra Patches Critical Vulnerabilities in BoKS Privileged works
Fortra disclosed and patched multiple vulnerabilities in Core Privileged Access Manager (BoKS), the Unix/Linux privileged access and credential-vaulting platform. NVD published the three critical CVEs on 2026-10-01 (advisories FI-2026-012, FI-2026-015 and FI-2026-017) and SecurityWeek reported them on 2026-10-03. Because the BoKS Master is the trust anchor for privileged access across the managed Unix estate, compromise of the Master or of the service accounts it provisions has outsized blast radius.
CVE-2026-79901 (CVSS 9.9, CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, CWE-338, advisory FI-2026-012): in deployments using BoKS keytab management, boks_keytabmd generates Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. SecurityWeek classes this as an authentication bypass and states exploitation requires knowledge of the service principal and an estimate of when the password was changed; an attacker with those inputs can narrow the candidate password space to a small set of timestamp seeds. NVD lists boks-server as affected from 0 up to (excluding) 9.0.0.6, with 9.0.0.6 onward unaffected.
CVE-2026-79898 (CVSS 9.1, CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H, CWE-78, advisory FI-2026-015): crlserver processes shell command substitution supplied in a certificate revocation list (CRL) URL. An authenticated user authorized to add CRL URLs through the BoKS Control Center (BCC), the WSI REST or SOAP API, or the cacrl command-line interface can cause commands to run as root on the BoKS Master. Exposure through BCC and the WSI APIs means the attack is network-reachable and does not depend on local sudo/suexec rules. NVD lists BoKS Manager 8.1.0.0 through 8.1.0.23 and 9.0.0.0 through 9.0.0.6 as affected.
CVE-2026-12627 (CVSS 9.8, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, CWE-121, advisory FI-2026-017): a stack-based buffer overflow in boks_autoregisterd that remote, unauthenticated attackers with network access can trigger during client response processing, causing memory corruption. NVD lists BoKS 8.1.0.0 through 8.1.0.23 and 9.0.0.0 through 9.0.0.6 as affected.
Five additional high- and medium-severity flaws were fixed: two heap buffer overflows, an out-of-bounds read, insecure temporary file handling and a further predictable password generation issue. The sources do not give their CVE identifiers. SecurityWeek reports no exploitation in the wild and no public PoC is mentioned in any source; a lookup of the CISA KEV catalog did not surface these CVEs (the check was against a partial excerpt, so treat it as unconfirmed).
Context: this is not the first 2026 BoKS disclosure. Fortra advisory FI-2026-007 (identified 2026-05-27, disclosed 2026-06-15) covered CVE-2026-9862, an unauthenticated OS command injection (CVSS 9.8) in the same boks_autoregisterd service, and CVE-2026-9863, command injection in the legacy tar-based client upgrade tooling. Repeated critical findings in boks_autoregisterd mean that exposure of that service deserves priority regardless of patch level.
The Fortra advisory pages returned HTTP 403 to the collector, so fixed release numbers are not confirmed here; defenders should take them from the Fortra advisories. Because NVD marks 9.0.0.6 as affected for CVE-2026-79898 and CVE-2026-12627 but unaffected for CVE-2026-79901, the fixed release for those two must be later than 9.0.0.6.
MITRE ATT&CK techniques used in TL-2026-2854
Execution
Persistence
Credential Access
Initial Access
Affected products and versions in Fortra Patches Critical Vulnerabilities in BoKS Privileged
- Fortra — Core Privileged Access Manager (BoKS) - BoKS Manager
Vulnerable versions: 8.1.0.0 through 8.1.0.23 (CVE-2026-79898, CVE-2026-12627); 9.0.0.0 through 9.0.0.6 (CVE-2026-79898, CVE-2026-12627); boks-server below 9.0.0.6 (CVE-2026-79901)
Fixed in: boks-server 9.0.0.6 and later (CVE-2026-79901, per NVD); Other fixed releases: see Fortra advisories FI-2026-015 and FI-2026-017 (not stated in collected sources)
Remediation for Fortra Patches Critical Vulnerabilities in BoKS Privileged
Patches
- Fortra BoKS fixed releases per advisories FI-2026-012, FI-2026-015 and FI-2026-017 (boks-server 9.0.0.6 and later is unaffected by CVE-2026-79901; fixed releases for the other two are not stated in the collected sources)
Immediate actions
- Apply the Fortra patches referenced in advisories FI-2026-012, FI-2026-015 and FI-2026-017 to all BoKS Manager/Master and server hosts
- Restrict who can add CRL URLs via BCC, the WSI REST/SOAP API and the cacrl CLI to a minimal set of trusted administrators
- Limit network exposure of boks_autoregisterd and the BCC/WSI interfaces to trusted management networks
Workarounds
- Rotate AD service-account passwords generated by boks_keytabmd once the patched version is deployed
- Where keytab management is not required, avoid enabling it until patched
Longer-term hardening
- Monitor the BoKS Master for crlserver spawning shells or unexpected child processes running as root
- Alert on boks_autoregisterd crashes or abnormal client registration traffic
- Review Kerberos/AD authentication activity for service accounts managed by BoKS keytab management
CVEs associated with Fortra Patches Critical Vulnerabilities in BoKS Privileged
CVE-2026-79901, CVE-2026-79898, CVE-2026-12627
Weaknesses (CWE) in Fortra Patches Critical Vulnerabilities in BoKS Privileged
CWE-338, CWE-78, CWE-121
Timeline of Fortra Patches Critical Vulnerabilities in BoKS Privileged
- Context: Fortra identifies the earlier BoKS issue later disclosed as FI-2026-007 (CVE-2026-9862, command injection in boks_autoregisterd); a separate advisory from the three flaws in this record.
- Context: Fortra publicly discloses FI-2026-007 covering CVE-2026-9862 (unauthenticated command injection, CVSS 9.8) and CVE-2026-9863 (legacy tar client upgrade command injection) in BoKS.
- NVD records for CVE-2026-79901 and CVE-2026-79898 are modified within hours of publication (79898 last modified 20:34 UTC), refining affected-version data.
- Fortra patches the three critical flaws plus five additional high/medium issues (two heap buffer overflows, an out-of-bounds read, insecure temporary file handling, predictable password generation) in BoKS.
- Fortra advisory FI-2026-017 and NVD publish CVE-2026-12627 (CVSS 9.8): unauthenticated stack-based buffer overflow in boks_autoregisterd.
- Fortra advisory FI-2026-015 and NVD publish CVE-2026-79898 (CVSS 9.1, 15:17 UTC): crlserver command injection executing as root on the BoKS Master via BCC, WSI REST/SOAP or cacrl.
- Fortra advisory FI-2026-012 and NVD publish CVE-2026-79901 (CVSS 9.9, 14:17 UTC): predictable, Unix-timestamp-seeded AD service-account password generation in boks_keytabmd; boks-server 9.0.0.6 onward unaffected.
- SecurityWeek reports the Fortra BoKS patches and notes no in-the-wild exploitation has been reported.
Sources cited for Fortra Patches Critical Vulnerabilities in BoKS Privileged
- SecurityWeek: Fortra Patches Critical Vulnerabilities in BoKS
- Fortra Product Security Advisories
- Fortra FI-2026-012 (CVE-2026-79901)
- Fortra FI-2026-015 (CVE-2026-79898)
- Fortra FI-2026-017 (CVE-2026-12627)
- NVD CVE-2026-79901
- NVD CVE-2026-79898
- NVD CVE-2026-12627
- NVD API record CVE-2026-79901
- NVD CVE-2026-9862 (prior BoKS boks_autoregisterd command injection, FI-2026-007)
- SentinelOne Vulnerability DB: CVE-2026-9863 (BoKS legacy tar client upgrade command injection)
- Rankiteo: Fortra BoKS command injection, June 2026
More in vulnerability
- Rejetto HTTP File Server (HFS) 3.x session forgery via predictable Math.random() signing key leads to unauthenticated admin access and RCE (CVE-2026-61500) under active exploitation
- Microsoft Reissues September 2026 Exchange Server Updates (V2) for CVE-2026-96940 Mailbox Authorization Flaw
- Dell Container Storage Modules (CSM) flaws enable unauthenticated admin access and root on Kubernetes nodes (CVE-2026-63688, CVE-2026-63692, CVE-2026-67269, CVE-2026-54472, CVE-2026-61421, CVE-2026-67273)
- GitLab AI Gateway critical RCE via prompt template sandbox escape (CVE-2026-90970)
- CISA adds two Zammad vulnerabilities to KEV: CVE-2026-102489 (session fixation to RCE) and CVE-2026-102490 (local privilege escalation to root), chained in an agentic-AI attack on DIVD
Detection coverage for TL-2026-2854
As of 2026-10-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2854 across Splunk SPL, Microsoft KQL and Sigma, covering 5 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.