Fortra Discloses Three Critical BoKS Vulnerabilities
Fortra issued eight security advisories for BoKS. Three flaws are rated critical and affect components used to manage privileged access.

Fortra BoKS vulnerabilities are addressed in eight security advisories published by the vendor on October 1, 2026, under identifiers FI-2026-012 through FI-2026-019. The patch bundle includes three critical flaws in the Core Privileged Access Manager (BoKS), designed to manage privileged access in Unix and Linux environments.
The most serious of the reported flaws, CVE-2026-79901, has a CVSS score of 9.9 out of 10. It concerns predictable passwords for Active Directory service accounts and, according to the available description, could lead to authentication bypass.
Fortra BoKS vulnerabilities include flaws with CVSS scores above 9
The critical flaws also include CVE-2026-79898, with a CVSS score of 9.1. This is command injection in the BoKS Manager crlserver component. The secondary description states that the vulnerability requires an authenticated user and that injected commands may be processed with root privileges.
The third critical flaw is identified as CVE-2026-12627 and has a CVSS score of 9.8. Fortra describes it as a remotely accessible stack buffer overflow in the boks_autoregisterd service. The flaw may cause memory corruption.
A separate advisory, FI-2026-016, concerns another remotely accessible, high-severity flaw in the BoKS Manager boks_portmux component. Fortra published eight advisories in total, while the available materials in this case do not allow the fixed versions to be reliably mapped to each of the eight CVEs individually.
Affected versions and guidance for administrators
The Canadian Centre for Cyber Security lists BoKS Manager boks-server versions older than 8.1.0.24 and 9.0.0.7 as affected. It recommends that organizations deploy the available updates.
Administrators should verify whether BoKS components are running in their environments, determine their exact versions, and compare them with the vendor’s information. Priority should be given to systems that use BoKS to manage administrative or other privileged access. The combination of possible authentication bypass, command execution, and remote memory corruption represents a relevant risk to administrative systems.
If the update cannot be deployed immediately, publicly available materials do not yet specify concrete alternative mitigations for all the flaws. Administrators should therefore monitor further guidance from Fortra and detailed information about the patch packages.
No confirmed exploitation so far
It has not been independently confirmed that any of the reported flaws is actively being exploited in practice. This does not change the need to urgently review the update status of BoKS deployments.
Further developments will depend primarily on whether Fortra publishes precise fix mappings for all CVEs and whether information emerges about active exploitation or additional mitigations for systems that cannot be updated immediately.
Sources
- Fortra Product Security Advisories – Primary list of the eight advisories FI-2026-012 through FI-2026-019 for BoKS dated October 1, 2026.
- Fortra FI-2026-017 – Confirms critical CVE-2026-12627, a remotely accessible stack buffer overflow in boks_autoregisterd, and a CVSS score of 9.8.
- Fortra FI-2026-016 – Confirms another high-severity, remotely accessible flaw in BoKS Manager boks_portmux.
- Canadian Centre for Cyber Security AV26-987 – Lists affected BoKS Manager boks-server versions older than 8.1.0.24 and 9.0.0.7 and recommends updating.
- SecurityWeek – Corroborates the release of fixes, the number of eight flaws, and details about CVE-2026-79901 and CVE-2026-79898; it does not report confirmed exploitation.
Verified and updated: 10/03/2026 15:24



