Skip to content
Fortra Addresses Critical Vulnerabilities in BoKS with Recent Patches

Fortra Addresses Critical Vulnerabilities in BoKS with Recent Patches

First seen 4 Oct 2026, 04:08 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 4, 2026 at 06:06 UTC
  • •Fortra patched eight vulnerabilities in BoKS, three of which are critical.
  • •CVE-2026-79901 allows authentication bypass with a CVSS score of 9.9.
  • •No known exploitation of these vulnerabilities has been reported.

Fortra has issued patches for eight vulnerabilities in its Core Privileged Access Manager (BoKS), including three critical vulnerabilities. The most severe, CVE-2026-79901, has a CVSS score of 9.9 and allows for authentication bypass due to predictable password generation from Unix timestamps. Another critical flaw, CVE-2026-79898, involves command injection that could let authenticated users execute shell commands as root. CVE-2026-12627, also critical, is a stack buffer overflow that may lead to memory corruption. The vulnerabilities affect BoKS Manager deployments using BoKS keytab for Active Directory service account management. Fortra has not reported any exploitation of these vulnerabilities in the wild. The company recommends that affected organizations apply the patches promptly to mitigate risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-06-11
CVE-2026-35273 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-13
CVE-2026-73570 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-27
CVE-2026-88772 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-27
CVE-2026-88771 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-01
Critical vulnerabilities disclosed
Fortra published patches for CVE-2026-79901, CVE-2026-79898, and CVE-2026-12627, all critical vulnerabilities in BoKS.
Securityweek
2026-10-01
CVE-2026-79898 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-01
CVE-2026-12627 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-01
CVE-2026-79901 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-03
Patches released for BoKS
Fortra released updates addressing eight vulnerabilities, including three critical ones, urging immediate application.
Securityweek

More articles in this cluster (2)

Following this threat?

Track CVE-2026-12627 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What are the critical CVEs patched?
The critical CVEs patched are CVE-2026-79901, CVE-2026-79898, and CVE-2026-12627.
How can I mitigate these vulnerabilities?
Apply the patches released by Fortra immediately to address the vulnerabilities.
Is there evidence of exploitation?
No, Fortra has not reported any exploitation of these vulnerabilities in the wild.