<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Privileged-Access-Management - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/privileged-access-management/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 03 Oct 2026 11:59:13 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/privileged-access-management/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Critical Vulnerabilities Patched in Fortra Core Privileged Access Manager (BoKS)</title><link>https://feed.craftedsignal.io/briefs/2026-10-fortra-boks-vulnerabilities/</link><pubDate>Sat, 03 Oct 2026 11:59:13 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-fortra-boks-vulnerabilities/</guid><description>Fortra released patches for three critical vulnerabilities in its Core Privileged Access Manager (BoKS) software, addressing authentication bypass, command injection, and memory corruption flaws.</description><content:encoded><![CDATA[<p>Fortra has disclosed and patched eight vulnerabilities affecting its Core Privileged Access Manager (BoKS), a centralized management solution for Unix and Linux environments. Among the eight, three are critical in severity and require immediate attention. CVE-2026-79901 (CVSS 9.9) allows for authentication bypass because Active Directory service account passwords are generated using a predictable pseudo-random sequence seeded with the current Unix timestamp. CVE-2026-79898 (CVSS 9.1) is a command injection flaw in the 'crlserver' component that can be exploited via BCC or the WSI REST/SOAP API to execute arbitrary commands as root. Finally, CVE-2026-12627 (CVSS 9.8) is a stack buffer overflow in the autoregistration functionality that could lead to memory corruption. While Fortra has not observed exploitation in the wild, the administrative nature of the impacted software makes these high-value targets for adversaries seeking to compromise privileged access infrastructure.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of these vulnerabilities could result in full administrative compromise of the BoKS environment, enabling unauthorized access to managed Unix/Linux fleets, privilege escalation to root, and potential persistence via memory corruption. The software is used for sensitive policy enforcement and access control, meaning impacted organizations risk the integrity and confidentiality of their privileged identity management infrastructure.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Patch all deployments of Fortra Core Privileged Access Manager (BoKS) immediately by applying the vendor-supplied updates.</li>
<li>Audit access to the WSI REST and SOAP APIs to ensure only authorized endpoints can interact with the 'crlserver' component.</li>
<li>Review Active Directory service account management policies for BoKS to identify potential reliance on the vulnerable 'keytab' generation process.</li>
<li>Monitor logs for unauthorized access attempts targeting BoKS administrative interfaces or API endpoints.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>vulnerability</category><category>authentication-bypass</category><category>privileged-access-management</category></item></channel></rss>