Skip to content
Critical OS Command Injection Vulnerability in Fortra BoKS Core

Critical OS Command Injection Vulnerability in Fortra BoKS Core

First seen 4 Oct 2026, 08:03 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 4, 2026 at 09:03 UTC
  • •CVE-2026-9862 is a critical OS command injection vulnerability with CVSS 9.8.
  • •The vulnerability allows unauthenticated remote attackers to execute commands with elevated privileges.
  • •Immediate patching is advised as there are no confirmed breaches but widespread scanning is occurring.

A critical OS command injection vulnerability, CVE-2026-9862, has been discovered in Fortra's BoKS Core Privileged Access Manager. This flaw, rated CVSS 9.8, allows unauthenticated remote attackers to execute arbitrary commands with elevated privileges via the boks_autoregisterd service. Organizations using BoKS for privileged access management are at risk of full system compromise. Although there are no confirmed breaches, the vulnerability is under active scrutiny in the security community. The flaw was publicly disclosed on June 15, 2026, and has led to widespread scanning attempts. Immediate patching is recommended, as the vulnerability is not currently listed in CISA's Known Exploited Vulnerabilities catalog. The affected service listens on TCP port 6507 and is critical for managing privileged access across enterprises.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-06-15
CVE-2026-9862 published
The vulnerability was publicly disclosed, detailing the OS command injection flaw in Fortra's BoKS Core.
Rescana
2026-06-17
NVD database updated
The National Vulnerability Database updated its records for CVE-2026-9862.
SentinelOne
2026-06-18
EPSS score recorded
The Exploit Prediction Scoring System recorded an EPSS score of 0.845% for CVE-2026-9862.
SentinelOne

More articles in this cluster (6)

Following this threat?

Track Fortra and CVE-2026-9862 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions of BoKS are affected?
The articles do not specify exact versions, but all instances using the boks_autoregisterd service are at risk.
Is there evidence of exploitation?
No confirmed exploitation has been reported, but widespread scanning attempts are noted.
What should organizations do now?
Organizations should apply the available patches immediately to mitigate the risk of exploitation.