Securityweek Fortra Addresses Critical Vulnerabilities in BoKS with Recent Patches
Article Content
- •Fortra patched eight vulnerabilities in BoKS, three of which are critical.
- •CVE-2026-79901 allows authentication bypass with a CVSS score of 9.9.
- •No known exploitation of these vulnerabilities has been reported.
Fortra has issued patches for eight vulnerabilities in its Core Privileged Access Manager (BoKS), including three critical vulnerabilities. The most severe, CVE-2026-79901, has a CVSS score of 9.9 and allows for authentication bypass due to predictable password generation from Unix timestamps. Another critical flaw, CVE-2026-79898, involves command injection that could let authenticated users execute shell commands as root. CVE-2026-12627, also critical, is a stack buffer overflow that may lead to memory corruption. The vulnerabilities affect BoKS Manager deployments using BoKS keytab for Active Directory service account management. Fortra has not reported any exploitation of these vulnerabilities in the wild. The company recommends that affected organizations apply the patches promptly to mitigate risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-12627 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What are the critical CVEs patched?
How can I mitigate these vulnerabilities?
Is there evidence of exploitation?
Continue Reading
Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…