CVE-2026-9862: Fortra Core Privileged Access Manager Server
Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.
Fortra's Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the autoregistration processing.
Affected products
- Fortra Core Privileged Access Manager Server: from 8.1.0.0, before 8.1.0.23 (fixed in 8.1.0.23); from 9.0.0.0, before 9.0.0.5 (fixed in 9.0.0.5)
Published 2026-06-15. Last modified 2026-07-28.