CVE-2026-9862: Fortra Core Privileged Access Manager Server

Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.

Fortra's  Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the autoregistration processing.

Affected products

  • Fortra Core Privileged Access Manager Server: from 8.1.0.0, before 8.1.0.23 (fixed in 8.1.0.23); from 9.0.0.0, before 9.0.0.5 (fixed in 9.0.0.5)

Published 2026-06-15. Last modified 2026-07-28.