CVE-2026-12627: Fortra Fortra's Core Privileged Access Manager Boks

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow vulnerability in boks_autoregisterd. A remote attacker with network access to the autoregistration service may be able to trigger memory corruption during client response processing.

Affected products

  • Fortra Fortra's Core Privileged Access Manager Boks: from 8.1.0.0, up to and including 8.1.0.23; from 9.0.0.0, up to and including 9.0.0.6

Published 2026-10-01. Last modified 2026-10-01.