Fortra has patched eight vulnerabilities in Core Privileged Access Manager (BoKS), including three critical flaws that could lead to authentication bypass, command injection, and remote memory corruption. The issues affect BoKS Manager deployments, with notable risks tied to Active Directory service account management and network-accessible interfaces such as BCC and WSI. #Fortra #CorePrivilegedAccessManager #BoKS #CVE-2026-79901 #CVE-2026-79898 #CVE-2026-12627
Keypoints
- Fortra released patches for eight BoKS vulnerabilities.
- CVE-2026-79901 can cause authentication bypass in AD service account management.
- CVE-2026-79898 is a critical command injection flaw in crlserver.
- CVE-2026-12627 is a stack buffer overflow in BoKS autoregistration.
- Five additional BoKS flaws affecting memory handling and password generation were also fixed.
Read More: https://www.securityweek.com/fortra-patches-critical-vulnerabilities-in-boks/