Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Vulnerabilities in Fortra’s BoKS Resolved

Critical Vulnerabilities in Fortra’s BoKS Resolved

Posted on October 3, 2026 By CWS

Fortra has addressed several vulnerabilities within its Core Privileged Access Manager (BoKS) by releasing crucial patches. Among these, three were identified as critical, underscoring the importance of updating.

Understanding Fortra’s BoKS

The BoKS solution is integral for organizations managing Unix and Linux systems, facilitating centralized policy implementation and access control. This recent development highlights a significant flaw affecting BoKS Manager setups that utilize keytab for managing Active Directory service accounts.

Details of the Critical Vulnerabilities

One of the critical vulnerabilities, tracked as CVE-2026-79901 with a CVSS score of 9.9, arises from a predictable password generation method linked to Unix timestamps. This flaw allows potential attackers to bypass authentication by estimating password change times and predicting possible passwords.

Another severe issue, CVE-2026-79898, scored at 9.1, involves command injection capabilities within the crlserver. Authenticated users could exploit this to execute shell commands with root privileges on the BoKS Master, posing significant risks.

Additional Vulnerabilities and Resolutions

Fortra also rectified a stack buffer overflow vulnerability, identified as CVE-2026-12627 with a CVSS score of 9.8, which could lead to memory corruption through BoKS’s autoregistration function. Furthermore, five other vulnerabilities of high to medium severity were addressed, including heap buffer overflows and insecure temporary file handling.

While no evidence currently suggests these vulnerabilities have been exploited in the wild, Fortra advises users to implement the patches promptly to safeguard against potential threats.

Future Outlook and Security Enhancements

Fortra’s swift response to these vulnerabilities is crucial for maintaining the security of its users. By patching these issues, they have reinforced the integrity of BoKS, ensuring continued protection for systems reliant on this management tool. Users are encouraged to stay informed through Fortra’s product security updates for ongoing protection.

Security Week News Tags:Active Directory, authentication bypass, BoKS, buffer overflow, command injection, CVE, Cybersecurity, Fortra, Linux, security patch, Unix, Vulnerabilities

Post navigation

Previous Post: Cybersecurity Innovations Transforming 2026 Landscape
Next Post: Doxx.net Secures $38 Million for AI Safety Platform

Related Posts

8 Cybersecurity Acquisitions Surpassed  Billion Mark in 2025 8 Cybersecurity Acquisitions Surpassed $1 Billion Mark in 2025 Security Week News
Cisco Addresses Sixth SD-WAN Zero-Day Exploit of 2026 Cisco Addresses Sixth SD-WAN Zero-Day Exploit of 2026 Security Week News
WhatsApp Introduces Scam Alert to Enhance Security WhatsApp Introduces Scam Alert to Enhance Security Security Week News
Kontext Security Secures M for AI Runtime Control Platform Kontext Security Secures $4M for AI Runtime Control Platform Security Week News
Critical Vulnerability Patched in Citrix NetScaler Critical Vulnerability Patched in Citrix NetScaler Security Week News
Ivanti EPM Update Patches Critical Remote Code Execution Flaw Ivanti EPM Update Patches Critical Remote Code Execution Flaw Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Doxx.net Secures $38 Million for AI Safety Platform
  • Critical Vulnerabilities in Fortra’s BoKS Resolved
  • Cybersecurity Innovations Transforming 2026 Landscape
  • Urgent Update: Dell Container Storage Security Vulnerabilities
  • Urgent Update: GitLab AI Gateway Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Doxx.net Secures $38 Million for AI Safety Platform
  • Critical Vulnerabilities in Fortra’s BoKS Resolved
  • Cybersecurity Innovations Transforming 2026 Landscape
  • Urgent Update: Dell Container Storage Security Vulnerabilities
  • Urgent Update: GitLab AI Gateway Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark