Rescana Critical OS Command Injection Vulnerability in Fortra BoKS Core
Article Content
- •CVE-2026-9862 is a critical OS command injection vulnerability with CVSS 9.8.
- •The vulnerability allows unauthenticated remote attackers to execute commands with elevated privileges.
- •Immediate patching is advised as there are no confirmed breaches but widespread scanning is occurring.
A critical OS command injection vulnerability, CVE-2026-9862, has been discovered in Fortra's BoKS Core Privileged Access Manager. This flaw, rated CVSS 9.8, allows unauthenticated remote attackers to execute arbitrary commands with elevated privileges via the boks_autoregisterd service. Organizations using BoKS for privileged access management are at risk of full system compromise. Although there are no confirmed breaches, the vulnerability is under active scrutiny in the security community. The flaw was publicly disclosed on June 15, 2026, and has led to widespread scanning attempts. Immediate patching is recommended, as the vulnerability is not currently listed in CISA's Known Exploited Vulnerabilities catalog. The affected service listens on TCP port 6507 and is critical for managing privileged access across enterprises.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Following this threat?
Track Fortra and CVE-2026-9862 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions of BoKS are affected?
Is there evidence of exploitation?
What should organizations do now?
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…