Fortra BoKS Patches Eight Flaws With Three Different Critical Paths
Fortra announced fixes for eight BoKS vulnerabilities on 1 October. Three are critical, but the headline number hides the operational decision: each reaches privileged infrastructure through a different doorway. Administrators must match the fix to the component and release line, not apply one version number across the whole platform.
Three critical flaws, three different trust boundaries
CVE-2026-79901, rated 9.9, affects deployments using BoKS keytab management. Fortra says the generated Active Directory service-account password can be predicted when an attacker knows the service principal, can estimate the password-change time and has suitable Kerberos ticket material. A standard authenticated AD account can ordinarily request the required service ticket. The condition does not normally require BoKS administration, access to the service host or access to its keytab.
CVE-2026-79898, rated 9.1, crosses a different boundary. An authenticated user who is authorised to add certificate revocation list URLs can inject shell command substitution that the BoKS Master processes as root. The reachable paths include BCC and WSI REST or SOAP interfaces, as well as the local cacrl command. The network paths still require the specific CRL-management authorisation.
CVE-2026-12627, rated 9.8, is the remote path. An attacker must be able to reach the autoregistration service and may then trigger stack-based memory corruption while the service processes a client response. Fortra describes memory corruption, not confirmed arbitrary code execution, so defenders should not stretch the claim beyond the advisory.
The other five still change the patch decision
- CVE-2026-79900, rated 6.5, lets an authenticated KSL client supply an oversized recognised digest name and write beyond a heap allocation.
- CVE-2026-79899 can expose CA secret or host private-key material through predictable temporary files to a local user able to read
BOKS_tmp. Fortra labels it High while displaying a CVSS score of 6.5. - CVE-2026-79896, rated 7.5, allows an unauthenticated malformed TLS ClientHello to terminate
boks_portmux. Repeated requests can sustain the interruption, but the vendor describes denial of service, not code execution. - CVE-2026-9864, rated 4.8, reduces the intended entropy of machine-account passwords generated by
adjoin, making prediction more feasible when generation time can be estimated. - CVE-2026-14316, rated 8.1, is a heap buffer overflow in
boks_sshdwhile it builds a revoked-key error message. The vendor’s CVSS vector includes user interaction.
Do not flatten the 8.1 patch line
For the KSL issue in boks-server, Fortra’s specific fix is 8.1.0.24 or 9.0.0.7. Canada’s cyber centre also lists BoKS Manager and its boks-server component as affected before those releases.
The full Core PAM platform has a different boundary. The Canadian notice lists versions before 8.1.0.30, 9.0.0.7 and 10.1.1.0. CSIRT Toscana expresses the same general platform boundary as 8.1.0.x below 8.1.0.30, 9.0.0.x below 9.0.0.7 and 10.1.0.x below 10.1.1.0. The difference between 8.1.0.24 and 8.1.0.30 is component-specific, not a contradiction.
Inventory keytab-managed service accounts, CRL administration paths and exposure of the autoregistration service first. Also identify hosts running boks_portmux or boks_sshd, then deploy the release for the exact component and branch. While change is in progress, restrict unneeded access to administration and autoregistration services. Review and rotate credentials where the predictable-password conditions apply.
No exploitation claim
None of the eight identifiers appeared in the current CISA Known Exploited Vulnerabilities catalogue snapshot checked on 4 October. Catalogue absence is not evidence that exploitation has not occurred. This report therefore treats the coordinated advisory set and its distinct exposure paths as the development, without claiming attacks in the wild.
Sources
- Fortra product security advisory index, 1 October 2026
- Fortra FI-2026-012 through FI-2026-019, 1 October 2026
- Canadian Centre for Cyber Security AV26-987, 2 October 2026
- CSIRT Toscana alert, updated 2 October 2026 at 15:39 Europe/Rome
- CISA Known Exploited Vulnerabilities catalogue, snapshot released 2 October 2026 at 15:19:38 UTC


