CVE-2026-9864: Fortra Core Privileged Access Manager Boks

Medium severity, CVSS 4.8. EPSS: 0.1% chance of exploitation in the next 30 days.

Fortra BoKS Server Agent contains a predictable password generation vulnerability in the adjoin utility. Machine-account passwords generated during Active Directory join or password renewal operations may have significantly less entropy than intended, making them more susceptible to prediction by an attacker who can estimate when the password was generated.

Affected products

  • Fortra Core Privileged Access Manager Boks: from 8.1.0.0, up to and including 8.1.0.29; from 9.0.0.0, up to and including 9.0.0.5

Published 2026-10-01. Last modified 2026-10-01.