{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/privileged-access-management/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:fortra:core_privileged_access_manager:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.9,"id":"CVE-2026-79901"},{"cvss":9.1,"id":"CVE-2026-79898"},{"cvss":9.8,"id":"CVE-2026-12627"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Core Privileged Access Manager (BoKS)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","authentication-bypass","privileged-access-management"],"_cs_type":"threat","_cs_vendors":["Fortra"],"content_html":"\u003cp\u003eFortra has disclosed and patched eight vulnerabilities affecting its Core Privileged Access Manager (BoKS), a centralized management solution for Unix and Linux environments. Among the eight, three are critical in severity and require immediate attention. CVE-2026-79901 (CVSS 9.9) allows for authentication bypass because Active Directory service account passwords are generated using a predictable pseudo-random sequence seeded with the current Unix timestamp. CVE-2026-79898 (CVSS 9.1) is a command injection flaw in the 'crlserver' component that can be exploited via BCC or the WSI REST/SOAP API to execute arbitrary commands as root. Finally, CVE-2026-12627 (CVSS 9.8) is a stack buffer overflow in the autoregistration functionality that could lead to memory corruption. While Fortra has not observed exploitation in the wild, the administrative nature of the impacted software makes these high-value targets for adversaries seeking to compromise privileged access infrastructure.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities could result in full administrative compromise of the BoKS environment, enabling unauthorized access to managed Unix/Linux fleets, privilege escalation to root, and potential persistence via memory corruption. The software is used for sensitive policy enforcement and access control, meaning impacted organizations risk the integrity and confidentiality of their privileged identity management infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch all deployments of Fortra Core Privileged Access Manager (BoKS) immediately by applying the vendor-supplied updates.\u003c/li\u003e\n\u003cli\u003eAudit access to the WSI REST and SOAP APIs to ensure only authorized endpoints can interact with the 'crlserver' component.\u003c/li\u003e\n\u003cli\u003eReview Active Directory service account management policies for BoKS to identify potential reliance on the vulnerable 'keytab' generation process.\u003c/li\u003e\n\u003cli\u003eMonitor logs for unauthorized access attempts targeting BoKS administrative interfaces or API endpoints.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-03T11:59:13Z","date_published":"2026-10-03T11:59:13Z","id":"https://feed.craftedsignal.io/briefs/2026-10-fortra-boks-vulnerabilities/","summary":"Fortra released patches for three critical vulnerabilities in its Core Privileged Access Manager (BoKS) software, addressing authentication bypass, command injection, and memory corruption flaws.","title":"Critical Vulnerabilities Patched in Fortra Core Privileged Access Manager (BoKS)","url":"https://feed.craftedsignal.io/briefs/2026-10-fortra-boks-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - Privileged-Access-Management","version":"https://jsonfeed.org/version/1.1"}