Fortra Patches Eight BoKS Flaws, Three Rated Critical
Fortra released patches for eight vulnerabilities in Core Privileged Access Manager (BoKS), including three critical bugs. The most severe, CVE-2026-79901 (CVSS 9.9), allows authentication bypass because AD service account passwords are generated from a predictable pseudo-random sequence seeded with the Unix timestamp. No exploitation in the wild has been reported.
- CVE-2026-79901 (CVSS 9.9): authentication bypass in BoKS Manager via predictable AD passwords
- CVE-2026-79898 (CVSS 9.1): command injection in crlserver executed as root on BoKS Master
- CVE-2026-12627 (CVSS 9.8): stack buffer overflow in autoregistration enabling remote memory corruption
- Five more high- and medium-severity flaws patched, including heap overflows and insecure temp files
Read next
Security