Fortra has taken swift action to address eight vulnerabilities in its Core Privileged Access Manager, known as BoKS. Among these are three critical flaws that posed significant security risks. BoKS plays a crucial role in centralizing management for Unix and Linux systems, ensuring policy enforcement and access control for organizations. A notable critical vulnerability, tracked as CVE-2026-79901 with a CVSS score of 9.9, could lead to an authentication bypass. This flaw arises from the method used to generate Active Directory service account passwords, which are based on a predictable sequence using the current Unix timestamp. Attackers with knowledge of the service principal and an estimation of the password-change time could create a set of potential passwords to verify offline.

Another critical issue, identified as CVE-2026-79898 with a CVSS score of 9.1, involves command injection. This could allow authenticated users to execute shell commands as root on the BoKS Master. The vulnerability can be exploited through BCC and the WSI REST or SOAP API, which are accessible over the network. Fortra also resolved a stack buffer overflow vulnerability, CVE-2026-12627, with a CVSS score of 9.8, that could lead to memory corruption if exploited remotely.

In addition to the critical flaws, Fortra patched five other vulnerabilities rated as high or medium severity. These include issues like heap buffer overflows, out-of-bounds reads, insecure temporary files, and predictable password generation. So far, there is no evidence to suggest that these vulnerabilities have been exploited in the wild. Fortra provides more detailed information on its product security page.