Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Tennessee’s top prison official resigning after botched execution of Christa Pike | Tennessee

    October 3, 2026

    The Best E-Readers That Aren’t a Kindle (2026): Kobo, Boox

    October 3, 2026

    Fortra Patches Critical Vulnerabilities in BoKS

    October 3, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Tennessee’s top prison official resigning after botched execution of Christa Pike | Tennessee
    • The Best E-Readers That Aren’t a Kindle (2026): Kobo, Boox
    • Fortra Patches Critical Vulnerabilities in BoKS
    • UK Finance Leaders Expect Tokenization to Reshape Markets
    • Italy’s Ustica enigma: Can French files solve mystery crash blamed on stray missile?
    • Spaniards protest housing crisis as Sánchez weighs snap vote – POLITICO
    • Tories plan to extend cuts beyond £47bn previously pledged, leak reveals | Conservatives
    • How to Collect CDs | WIRED
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, October 3
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Fortra Patches Critical Vulnerabilities in BoKS

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 3, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Fortra has released patches for eight vulnerabilities in Core Privileged Access Manager (BoKS), including three critical-severity bugs.

    BoKS provides organizations with central management of Unix and Linux fleets, enabling policy enforcement and access control across accounts.

    On Thursday, the company warned that BoKS Manager deployments relying on BoKS keytab for Active Directory service account management are affected by a critical flaw leading to authentication bypass.

    Tracked as CVE-2026-79901 (CVSS score of 9.9), the issue exists because AD service account passwords are generated from a “predictable pseudo-random sequence seeded with the current Unix timestamp.”

    “An attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify candidates offline,” Fortra warned.

    The company underlined that an attacker could exploit the flaw if they knew the affected service principal, could estimate the password-change time, and had suitable Kerberos ticket material.

    Advertisement. Scroll to continue reading.

    “A standard authenticated Active Directory account can ordinarily request a service ticket for an SPN assigned to the affected account; administrative access to BoKS, the service host, or its keytab is not normally required. A previously captured service ticket can alternatively provide offline verification material,” it said.

    The second critical bug, CVE-2026-79898 (CVSS score of 9.1), is a command injection defect in crlserver that could allow an authenticated user to substitute shell commands that would be processed as root on the BoKS Master.

    According to Fortra, the vulnerability is exploitable through BCC and the WSI REST or SOAP API. BCC and WSI can be accessed over the network without a local sudo or suexec rule.

    The company also resolved CVE-2026-12627 (CVSS score of 9.8), a stack buffer overflow in BoKS’s autoregistration functionality that could allow a remote attacker to trigger memory corruption.

    Additionally, Fortra patched five high- and medium-severity BoKS flaws: heap buffer overflows, out-of-bounds read, insecure temporary file, and predictable password generation.

    The company makes no mention of any of these vulnerabilities being exploited in the wild. Additional information can be found on Fortra’s product security page.

    Related: Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks

    Related: Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action

    Related: WatchGuard Patches Critical Fireware OS Code Injection Vulnerability

    Related: Chrome, Firefox Updates Patch Over 100 Vulnerabilities

    BoKS critical Fortra Patches Vulnerabilities
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Danish university DTU breach exposes data of up to 200,000 people

    doxx.net Raises $38 Million to Prevent AI Agent-on-the-Internet Misadventures

    Kiteworks patches max severity code injection vulnerability

    Dell asks admins to patch max severity CSM flaws as soon as possible

    Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs

    CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Tennessee’s top prison official resigning after botched execution of Christa Pike | Tennessee

    October 3, 2026

    The Best E-Readers That Aren’t a Kindle (2026): Kobo, Boox

    October 3, 2026

    Fortra Patches Critical Vulnerabilities in BoKS

    October 3, 2026

    UK Finance Leaders Expect Tokenization to Reshape Markets

    October 3, 2026
    Latest Posts

    Google’s top hacker hunter explains why hacking groups get codenames

    August 8, 2026

    Nicola Sturgeon ‘has not spoken to’ estranged husband, Peter Murrell, since he was jailed | Nicola Sturgeon

    August 8, 2026

    Amid Abuse Claims Against Max Miller, This Democrat Thinks He Can Win His Seat

    August 8, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Tennessee’s top prison official resigning after botched execution of Christa Pike | Tennessee

    October 3, 2026

    The Best E-Readers That Aren’t a Kindle (2026): Kobo, Boox

    October 3, 2026

    Fortra Patches Critical Vulnerabilities in BoKS

    October 3, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.