Fortra's BoKS 9.9 advisory names no fixed version, and the update does not secure passwords already generated
Fortra patched eight BoKS flaws on 1 October, three of them critical, and states no exploitation. For the 9.9, a password-generation flaw, its CVE record says updating does not secure passwords already generated, a sentence its advisory page omits.
By Parminder Kumar Sharma · · 17 min read

The advisory page for the 9.9 names no version and no fix. The CVE record names both
Fortra's advisory FI-2026-012, for the BoKS flaw it scores 9.9, does not say which versions are affected, which version fixes it, or what to do about passwords that have already been generated. Its 'Affected Products' row is empty, and so is that row on the seven other BoKS advisories Fortra published the same day (read at 11:54 BST on Sunday 4 October 2026, and again, unchanged, at 12:19 BST). The CVE record Fortra filed at 13:52 UTC on 1 October, 2 days 21 hours before our reads (derived), says all three. It gives the affected range as boks-server below 9.0.0.6 and the fix as boks-server 9.0.0.7, and then adds: 'Installing the update does not secure passwords generated by an affected release.'
The flaw, CVE-2026-79901, is in boks_keytabmd, the part of Fortra's Core Privileged Access Manager (BoKS) that generates passwords for Active Directory (AD) service accounts when 'BoKS keytab management' is in use. Fortra says the passwords come from 'a predictable pseudo-random sequence seeded with the current Unix timestamp', so an attacker who knows the service principal and can estimate the password-change time 'can reproduce a limited candidate set and verify candidates offline'. SecurityWeek reported the eight advisories on 3 October. This briefing is built from Fortra's own pages, the CVE.org and NVD records, CISA's catalogue and Fortra's release notes.
What that does not establish. It does not say anyone has used the flaw. Fortra's advisories carry no exploitation statement, CISA's coordinator records 'Exploitation: none' on all eight CVE records (14:41 to 16:32 UTC on 1 October), and none of the eight is in CISA's Known Exploited Vulnerabilities (KEV) catalogue (version 2026.10.02, read at 10:58 UTC and again at 11:18 UTC on 4 October). It does not say how many organisations use keytab management, what the affected service accounts can do, or how large the 'limited candidate set' is, because Fortra does not say. And it does not establish an 'authentication bypass', the phrase SecurityWeek uses in its standfirst and text. That is a fair reading of where the flaw ends, since an attacker who recovers a password can sign in as the account (inference), but it is the reporter's phrase and neither Fortra's advisory nor its CVE record contains it.
Where the 0.1 went. Fortra's vector for the flaw is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. Our recomputation with the CVSS 3.1 formulas gives 9.9, and changing only PR:L to PR:N gives 10.0, the same arithmetic as in our briefing on GitLab's AI Gateway 9.9. The missing 0.1 is the login, and Fortra's text says what the login is: 'a standard authenticated Active Directory account' can ordinarily request a service ticket for the affected account's service principal name (SPN), and 'administrative access to BoKS, the service host, or its keytab is not normally required'. A previously captured service ticket 'can alternatively provide offline verification material'. Our Dell briefing made the same point about a different 9.9: the score names a precondition, and the precondition is the thing to look for.
Every score in this briefing is Fortra's. Fortra is the numbering authority for its own CVE records, wrote all eight descriptions and sells the product. NVD lists CVE-2026-79901 as Deferred and the other seven as Awaiting Analysis, so NIST has scored none of them (read at 10:57 UTC and again, unchanged, at 11:18 UTC). That is not a charge against Fortra's numbers, which reproduce from their vectors with one exception covered below. It is the reason to check them.
Stated and not stated, as of 12:20 BST on Sunday 4 October
What Fortra's advisory page, Fortra's CVE record and Fortra's release notes state about CVE-2026-79901, and what none of them states. Sources: FI-2026-012, CVE.org, NVD, CISA KEV and Fortra's BoKS Manager release notes, read on 4 October 2026.
- Question
- Is it exploited?
- Stated
- Fortra's pages are silent. CISA's coordinator: 'Exploitation: none', 1 October. Not in KEV.
- Not stated
- Anything after 1 October, or who has looked.
- Question
- Who is affected?
- Stated
- Only BoKS Manager deployments using keytab management for AD service accounts. Administrator-supplied initial passwords are not affected.
- Not stated
- How many deployments. The advisory page's Affected Products row, which is empty.
- Question
- Which versions?
- Stated
- CVE record: boks-server from 0 up to below 9.0.0.6.
- Not stated
- Whether 9.0.0.6 itself is affected. Whether 8.1 is fixed, and in which build.
- Question
- What fixes it?
- Stated
- boks-server 9.0.0.7 on the active Master, then restart BoKS before generating replacement passwords (CVE record). The 9.0.0.7 notes list cryptographic randomness for AD service-account passwords.
- Not stated
- Any fix for the 8.1 line. The 8.1.0.24 notes do not list one.
- Question
- Is the update enough?
- Stated
- No. 'Installing the update does not secure passwords generated by an affected release.' Rotate, then rebuild keytabs (CVE record).
- Not stated
- Any of this on the advisory page. Any indicators or detection guidance.
- Question
- What does the attacker get?
- Stated
- A candidate password for the service account, checked offline. Fortra's vector scores confidentiality, integrity and availability High, scope Changed.
- Not stated
- What the account can reach, how many candidates there are, or any 'authentication bypass'. That phrase is SecurityWeek's.
| Question | Stated | Not stated |
|---|---|---|
| Is it exploited? | Fortra's pages are silent. CISA's coordinator: 'Exploitation: none', 1 October. Not in KEV. | Anything after 1 October, or who has looked. |
| Who is affected? | Only BoKS Manager deployments using keytab management for AD service accounts. Administrator-supplied initial passwords are not affected. | How many deployments. The advisory page's Affected Products row, which is empty. |
| Which versions? | CVE record: boks-server from 0 up to below 9.0.0.6. | Whether 9.0.0.6 itself is affected. Whether 8.1 is fixed, and in which build. |
| What fixes it? | boks-server 9.0.0.7 on the active Master, then restart BoKS before generating replacement passwords (CVE record). The 9.0.0.7 notes list cryptographic randomness for AD service-account passwords. | Any fix for the 8.1 line. The 8.1.0.24 notes do not list one. |
| Is the update enough? | No. 'Installing the update does not secure passwords generated by an affected release.' Rotate, then rebuild keytabs (CVE record). | Any of this on the advisory page. Any indicators or detection guidance. |
| What does the attacker get? | A candidate password for the service account, checked offline. Fortra's vector scores confidentiality, integrity and availability High, scope Changed. | What the account can reach, how many candidates there are, or any 'authentication bypass'. That phrase is SecurityWeek's. |
Two gaps matter more than the rest. The first is the range. The CVE record excludes 9.0.0.6 itself, yet the first release note that mentions a cure is for server 9.0.0.7, and the five other server records in the batch treat 9.0.0.6 as affected. The safe reading is that 9.0.0.6 is affected (inference).
The second is the 8.1 line. Fortra's release notes say keytab management for AD service accounts reached BoKS 8.1 on 30 October 2024 (server s-8.1.0.13) and the 9.0 line on 17 December 2025 (server s-9.0.0.3). The CVE record's range starts at version 0, so on its face it covers 8.1 with keytab management too (inference), but the only fix it names is 9.0.0.7, and the 8.1.0.24 release notes of 2 October list no such change. A team on 8.1 that reads the record as written has a flaw and no stated build. The record does not say that the weak generator has been there since the feature shipped, so the 701 days below measure how long the feature has been on sale, not how long the flaw has been exploitable.
A privileged access manager holds the keys, and these flaws sit in the building around them
The name 'Privileged Access Manager' says what the product guards and nothing about what guards the product. Fortra's own datasheet describes BoKS as a way to 'define and enforce who is granted elevated privilege, when, from where, and how' across a Unix and Linux estate run as 'one centrally managed security domain', and it lists PCI DSS, SOX and Basel III among the regimes it supports. A flaw in the Master that serves that policy is a key-holder problem, not an ordinary server bug: whoever controls the Master controls what it tells every host about who may be root (inference from the datasheet's description).
The eight advisories show where the building is open: an autoregistration daemon, a TLS parser in boks_portmux, a log service, two administration paths (the BCC console and the WSI REST and SOAP interface), a password generator, a certificate utility that writes predictable temporary files on the Master, an SSH daemon, and the machine-account password code in adjoin. Fortra's index lists 12 BoKS advisories since 17 June 2025, two in 2025 and ten in 2026, eight of them on 1 October (derived from the index). Six of the eight CVE records say the discovery was internal and none credits an outside researcher. A vendor finding its own flaws counts in its favour; the advisories do not say how it found them.
We found no source that counts BoKS customers in the UK or anywhere, and a search found no UK NCSC alert naming these CVEs at the time of reading. Exposure is therefore a question for your own inventory, not something this record can answer.
Three criticals, three doors, probably three teams
Only one of the three criticals needs the keytab feature. The other two sit in Master components: autoregistration, and certificate revocation list (CRL) handling, which the record says matters for deployments that process configured CRL URLs. The three are reached by different people: anyone with network access to the autoregistration port, a user holding a delegated CRL right, and any authenticated AD account. The fixes land with different teams too, network, Unix administration and the AD team, which is our inference from the table and not something Fortra says.
The three critical flaws as Fortra describes them. Sources: Fortra advisories FI-2026-012, 015 and 017, CVE.org records and BoKS Manager release notes, read 4 October 2026.
- CVE and score
- CVE-2026-79901, 9.9. boks_keytabmd, keytab management only
- What the record says the attacker needs
- The service principal, an estimate of the password-change time and Kerberos ticket material. A standard AD account can ordinarily request a ticket; a captured ticket also serves.
- Fixed in, as stated
- 9.0.0.7. The 8.1 line: not stated.
- CVE and score
- CVE-2026-79898, 9.1. crlserver, command injection
- What the record says the attacker needs
- An authenticated user allowed to add CRL URLs: the CRLS add right in BCC, the addCACRLURL call in WSI, or the cacrl command. Commands run as root on the Master.
- Fixed in, as stated
- 8.1.0.24 or 9.0.0.7.
- CVE and score
- CVE-2026-12627, 9.8. boks_autoregisterd, stack buffer overflow
- What the record says the attacker needs
- Network access to the autoregistration service, TCP 6507 by default. No account.
- Fixed in, as stated
- 8.1.0.24 or 9.0.0.7.
| CVE and score | What the record says the attacker needs | Fixed in, as stated |
|---|---|---|
| CVE-2026-79901, 9.9. boks_keytabmd, keytab management only | The service principal, an estimate of the password-change time and Kerberos ticket material. A standard AD account can ordinarily request a ticket; a captured ticket also serves. | 9.0.0.7. The 8.1 line: not stated. |
| CVE-2026-79898, 9.1. crlserver, command injection | An authenticated user allowed to add CRL URLs: the CRLS add right in BCC, the addCACRLURL call in WSI, or the cacrl command. Commands run as root on the Master. | 8.1.0.24 or 9.0.0.7. |
| CVE-2026-12627, 9.8. boks_autoregisterd, stack buffer overflow | Network access to the autoregistration service, TCP 6507 by default. No account. | 8.1.0.24 or 9.0.0.7. |
The scores, recomputed. We recomputed all eight vectors with the CVSS 3.1 formulas. Seven match the figure on Fortra's advisory page. The eighth, CVE-2026-79899, is shown on its advisory page as 6.5 and labelled High; its vector computes to 7.9, which is what the CVE record and NVD show. The 9.1 is lower than the 9.9 because it needs a high-privilege role (PR:H) rather than a low one (PR:L), both with scope changed. The 9.8 needs no account (PR:N) but is scored scope unchanged, which is why it sits between them.
What the three do not establish. The 9.8 is described only as memory corruption: the advisory says a remote attacker 'may be able to trigger memory corruption' and says nothing about code execution, although Fortra's vector scores full impact. The 9.1 is root on the Master, but only for a user who already holds the CRL right, and the CVE record names the rights. And the 9.9 is a password that has to be found from ticket material, at a cost to the attacker that the advisory does not give.
The 9.9 is about how a secret was made, and an update does not reach back
This is the same weakness class as CVE-2026-61500 in Rejetto HFS: both are filed as CWE-338, a cryptographically weak pseudo-random number generator. That is where the likeness ends. HFS used a weak generator for a session-signing key and leaked the generator's outputs at login, so an attacker needed no account, and an update closed it. BoKS used one for passwords that now exist in Active Directory. The record describes no leak, the attacker starts from an ordinary AD account or an old ticket, no source reports exploitation, and the update fixes the generator without changing a single password already made.
Why the update is half a fix. A password is a stored value. If it was set from a weak sequence, the weakness lives in the value and stays in Active Directory and in the keytab files until the password changes. Fortra's CVE record therefore gives a sequence, not a version. Upgrade the active BoKS Master to 9.0.0.7 and restart BoKS before generating replacement passwords. Rotate every affected or uncertain service-account password through keytab management and confirm the new key version has been distributed. Once the domain's maximum service-ticket lifetime plus a clock-skew allowance has passed, rebuild the keytabs so they keep only the current key version, then redistribute them, restart dependent services and test Kerberos authentication. If compromise is suspected, rotate and rebuild at once rather than wait for tickets to expire. None of that is on the advisory page.
What a defender can and cannot see. The advisory's word is 'offline'. If candidates are checked offline against ticket material, no failed sign-in reaches a domain controller (inference). The one visible step is the ticket request, which is ordinary traffic: Windows records each one on domain controllers as event 4769, 'A Kerberos service ticket was requested'. A review of requests for the managed accounts' SPNs may show an unexpected requester, and a clean review proves little. A ticket captured before a password was rotated can still be tested against the old password afterwards (inference), and the record does not say how far back a ticket could have been taken.
Why the accounts matter as much as the flaw. The attacker's prize is a service account, and these are the identities that often have no human owner. Our briefing on seven compromised Microsoft 365 accounts found that every account that fell in that campaign was a service account with no human behind it. What a BoKS-managed service account can reach in your estate is not in Fortra's advisory, and it is the fact that sets the real severity.
The autoregistration daemon has now needed two critical fixes in 108 days
On 15 June 2026 Fortra fixed CVE-2026-9862, a 9.8 OS command injection in boks_autoregisterd, in builds 8.1.0.23 and 9.0.0.5. On 1 October it disclosed CVE-2026-12627, a 9.8 stack buffer overflow in the same daemon, 108 days later (derived). Both need only network access to the service, which listens on TCP port 6507 by default. Both come with the same stated control, restricting network access to it, and Fortra's records add that the service can be disabled if autoregistration is not needed. CISA's coordinator marks both 'Automatable: yes', and neither is in the KEV catalogue.
That does not show the two flaws are related, or that anyone is probing port 6507; no source says either. One wording mismatch is worth knowing about. Fortra's October release notes list the fix as 'Buffer overflow in autoregistration proxy version handling', while the advisory describes 'client response processing'. The notes point to a README for CVE references that we could not read, so we cannot confirm from public pages that these are the same change.
All eight, with the versions Fortra gives
The eight BoKS advisories of 1 October 2026. Scores are Fortra's and reproduce from the vectors except where noted. Sources: Fortra advisories FI-2026-012 to 019, CVE.org records, BoKS Manager release notes, read 4 October 2026.
- CVE and score
- CVE-2026-79901, 9.9 Critical
- Where
- boks_keytabmd: predictable AD service-account passwords
- Fixed in, as stated
- Server 9.0.0.7. The 8.1 line: not stated.
- CVE and score
- CVE-2026-12627, 9.8 Critical
- Where
- boks_autoregisterd: stack buffer overflow
- Fixed in, as stated
- Server 8.1.0.24 or 9.0.0.7.
- CVE and score
- CVE-2026-79898, 9.1 Critical
- Where
- crlserver: command injection, root on the Master
- Fixed in, as stated
- Server 8.1.0.24 or 9.0.0.7.
- CVE and score
- CVE-2026-14316, 8.1 High
- Where
- boks_sshd: heap overflow in revoked-key handling
- Fixed in, as stated
- Affected: below 8.1.0.30, and 10.1.0.0 to below 10.1.1.0. Record says 'a patched version'; October notes list client c-8.1.0.30.
- CVE and score
- CVE-2026-79899, 7.9 High (advisory page: 6.5)
- Where
- bccgethostcert: predictable temporary files on the Master
- Fixed in, as stated
- Server 8.1.0.24 or 9.0.0.7. Workaround: restrictive umask.
- CVE and score
- CVE-2026-79896, 7.5 High
- Where
- boks_portmux: TLS ClientHello out-of-bounds read, denial of service
- Fixed in, as stated
- Server 8.1.0.24 or 9.0.0.7.
- CVE and score
- CVE-2026-79900, 6.5 Medium
- Where
- boks_ksllogsd: heap overflow, needs a valid log-client identity
- Fixed in, as stated
- Server 8.1.0.24 or 9.0.0.7.
- CVE and score
- CVE-2026-9864, 4.8 Medium
- Where
- adjoin: weak machine-account passwords on AD join or renewal
- Fixed in, as stated
- Client newer than 8.1.0.29 or 9.0.0.5; October notes list c-8.1.0.30.
| CVE and score | Where | Fixed in, as stated |
|---|---|---|
| CVE-2026-79901, 9.9 Critical | boks_keytabmd: predictable AD service-account passwords | Server 9.0.0.7. The 8.1 line: not stated. |
| CVE-2026-12627, 9.8 Critical | boks_autoregisterd: stack buffer overflow | Server 8.1.0.24 or 9.0.0.7. |
| CVE-2026-79898, 9.1 Critical | crlserver: command injection, root on the Master | Server 8.1.0.24 or 9.0.0.7. |
| CVE-2026-14316, 8.1 High | boks_sshd: heap overflow in revoked-key handling | Affected: below 8.1.0.30, and 10.1.0.0 to below 10.1.1.0. Record says 'a patched version'; October notes list client c-8.1.0.30. |
| CVE-2026-79899, 7.9 High (advisory page: 6.5) | bccgethostcert: predictable temporary files on the Master | Server 8.1.0.24 or 9.0.0.7. Workaround: restrictive umask. |
| CVE-2026-79896, 7.5 High | boks_portmux: TLS ClientHello out-of-bounds read, denial of service | Server 8.1.0.24 or 9.0.0.7. |
| CVE-2026-79900, 6.5 Medium | boks_ksllogsd: heap overflow, needs a valid log-client identity | Server 8.1.0.24 or 9.0.0.7. |
| CVE-2026-9864, 4.8 Medium | adjoin: weak machine-account passwords on AD join or renewal | Client newer than 8.1.0.29 or 9.0.0.5; October notes list c-8.1.0.30. |
Fortra's release notes list the server builds 8.1.0.24 and 9.0.0.7 and the client build 8.1.0.30 under 2 October, a day after the advisories and CVE records. We cannot tell from the public pages when the packages became downloadable. The note for 9.0.0.7 carries a known issue: Entra ID authentication 'should not be used' with server s-9.0.0.7 and client c-9.0.0.6, and anyone using it is told to postpone the upgrade until client c-9.0.0.7 is available. A 9.0 domain with both Entra ID and keytab management has to weigh that against the 9.9, and Fortra's pages do not say how (not stated). It is a reason to plan the upgrade, not to skip it, because the 9.0 line has no other stated fix for the 9.9.
What UK organisations should do, in the order worth doing
Items marked 'Stated by Fortra' are in Fortra's records. Items marked 'Judgement' are ours, and are labelled so you can weigh them.
Take this with you
Actions, in order
- Judgement: inventory every BoKS Master, Replica and Server Agent with its build (server s-, client c-, and the WSI, BCC and SSH packages). Record which line each domain runs, 8.1 or 9.0, and any boks-ssh 10.1 package.
- Judgement: find out whether BoKS keytab management is used, which AD service accounts it manages and when each password was last generated. It shipped on 8.1 on 30 October 2024 and on 9.0 on 17 December 2025, so assume any domain on those lines may have used it.
- Stated by Fortra: restrict network access to boks_autoregisterd (TCP 6507 by default) and to the boks_portmux listeners, and disable boks_autoregisterd if autoregistration is unused. Judgement: apply the same limit to BCC and WSI, for which the record gives no workaround, so that only the hosts and administrator networks that need them can connect. Do this first, since it does not depend on the upgrade, and remember it does not address the 9.9.
- Stated by Fortra: upgrade to server build 8.1.0.24 or 9.0.0.7 as the installed line requires, and to client 8.1.0.30 for the boks_sshd and adjoin fixes, and confirm the updated daemons are running. Read Fortra's Entra ID known issue before moving a 9.0 domain that uses Entra ID.
- Stated by Fortra, for the 9.9: after upgrading the active Master to 9.0.0.7 and restarting BoKS, rotate every affected or uncertain AD service-account password through keytab management and confirm the new key version is distributed. Rebuild the keytabs once the maximum service-ticket lifetime plus clock skew has passed, then test Kerberos authentication. Rotate and rebuild at once if compromise is suspected.
- Judgement: if any keytab-managed domain runs 8.1, ask Fortra in writing which build fixes CVE-2026-79901 there, and treat those passwords as weak until it answers.
- Stated by Fortra, for CVE-2026-9864: after moving to a fixed client, rotate machine-account passwords that adjoin generated on affected builds (up to 8.1.0.29 and 9.0.0.5).
- Judgement: review the AD service accounts BoKS manages. For each, name an owner, list its SPNs and check what it can reach. Review Kerberos service-ticket requests for those SPNs on your domain controllers (Windows event 4769) for requesters that are not the expected clients, and keep the result in the incident record. Treat a clean result as weak evidence.
- Judgement: review who holds the CRLS add right in BCC and the addCACRLURL permission in WSI, which the CVE record names as the preconditions for the 9.1, and who has local access to BOKS_tmp on each Master. Stated by Fortra: until the temporary-file fix is installed, the workaround is a restrictive umask and removal of stale bcccax and bcccreds files.
- Judgement: re-check Fortra's advisory pages, NVD and CISA's catalogue before relying on this page. At the times above the Affected Products rows were empty, NVD had scored none of the eight and the catalogue listed none.
The question that exposes the gap
The attacker in Fortra's advisory has to estimate when each password was changed. The defender should be able to state it exactly, and cannot rotate or review an account that nobody can name.
Can you list every Active Directory service account whose password your privileged access tool generated, and the date each one was last changed?
Key facts
Sources
- PrimaryProduct Security Advisories index, read in a browser at 11:54 BST on 4 October 2026 after curl met a JavaScript challenge. Used for the eight BoKS rows dated 1 October and the count of 12 BoKS advisories since June 2025.Fortraaccessed 2026-10-04
- PrimaryAdvisory FI-2026-012, CVE-2026-79901: the 9.9: boks_keytabmd predictable AD service-account passwords. Read for the description, severity, vector, discovery date 25 August and the empty Affected Products row.Fortraaccessed 2026-10-04
- PrimaryAdvisory FI-2026-013, CVE-2026-79900: heap overflow in KSL checksum initialisation, 6.5 Medium, fix boks-server 8.1.0.24 or 9.0.0.7.Fortraaccessed 2026-10-04
- PrimaryAdvisory FI-2026-014, CVE-2026-79899: bccgethostcert insecure temporary file. Page shows 6.5 labelled High, which does not match its own vector (7.9).Fortraaccessed 2026-10-04
- PrimaryAdvisory FI-2026-015, CVE-2026-79898: crlserver command injection, 9.1, root on the BoKS Master through BCC, WSI or cacrl.Fortraaccessed 2026-10-04
- PrimaryAdvisory FI-2026-016, CVE-2026-79896: boks_portmux TLS ClientHello out-of-bounds read, 7.5 High.Fortraaccessed 2026-10-04
- PrimaryAdvisory FI-2026-017, CVE-2026-12627: boks_autoregisterd stack buffer overflow, 9.8.Fortraaccessed 2026-10-04
- PrimaryAdvisory FI-2026-018, CVE-2026-9864: adjoin machine-account password generation, 4.8 Medium.Fortraaccessed 2026-10-04
- PrimaryAdvisory FI-2026-019, CVE-2026-14316: boks_sshd heap overflow in revoked-key handling, 8.1 High.Fortraaccessed 2026-10-04
- PrimaryAdvisory FI-2026-007, CVE-2026-9862 (15 June 2026): 9.8 command injection in boks_autoregisterd, port 6507, fixed in 8.1.0.23 and 9.0.0.5.Fortraaccessed 2026-10-04
- PrimaryCVE.org record for CVE-2026-79901, the 9.9. Read as JSON from the CVE Services API at 10:56 UTC on 4 October: published 13:52 UTC on 1 October, affected range below 9.0.0.6, fix 9.0.0.7, the workaround that rotation is needed after the update, and CISA-ADP's SSVC entry.CVE Programaccessed 2026-10-04
- PrimaryCVE.org record for CVE-2026-79898, the 9.1: rights required in BCC and WSI, affected 8.1.0.0 to 8.1.0.23 and 9.0.0.0 to 9.0.0.6.CVE Programaccessed 2026-10-04
- PrimaryCVE.org record for CVE-2026-12627, the 9.8: autoregistration port 6507 by default, workaround to restrict or disable the service.CVE Programaccessed 2026-10-04
- PrimaryCVE.org record for CVE-2026-79900, KSL heap overflow: affected below 8.1.0.24 and below 9.0.0.7.CVE Programaccessed 2026-10-04
- PrimaryCVE.org record for CVE-2026-79899, temporary file flaw: CVE record scores 7.9 HIGH, workaround umask 077.CVE Programaccessed 2026-10-04
- PrimaryCVE.org record for CVE-2026-79896, portmux read: workaround restrict network access.CVE Programaccessed 2026-10-04
- PrimaryCVE.org record for CVE-2026-9864, adjoin: affected up to 8.1.0.29 and 9.0.0.5, rotate machine-account passwords.CVE Programaccessed 2026-10-04
- PrimaryCVE.org record for CVE-2026-14316, boks_sshd: affected below 8.1.0.30 and 10.1.0.0 to below 10.1.1.0.CVE Programaccessed 2026-10-04
- PrimaryCVE.org record for CVE-2026-9862, the June autoregistration command injection, 9.8, fixed 15 June 2026.CVE Programaccessed 2026-10-04
- PrimaryNVD records for all eight CVEs, read as raw JSON from the NVD API between 10:57 and 10:58 UTC on 4 October. Used for status (one Deferred, seven Awaiting Analysis), Fortra as the only scorer and CISA-ADP's SSVC entries.NIST NVDaccessed 2026-10-04
- PrimaryKnown Exploited Vulnerabilities catalogue, read as the JSON feed at 10:58 UTC on 4 October: version 2026.10.02, released 2 October 15:19 UTC, 1,733 entries, none of the eight BoKS CVEs and no BoKS entry.CISAaccessed 2026-10-04
- PrimaryBoKS Manager release notes, read in full at 10:58 UTC on 4 October. Used for builds s-8.1.0.24, s-9.0.0.7 and c-8.1.0.30 dated 2 October, the Entra ID known issue, the keytab management release dates and the June autoregistration fix.Fortraaccessed 2026-10-04
- PrimaryBoKS Web Services Interface release notes: keytab management functions added 30 October 2024 and require server s-8.1.0.13 or later.Fortraaccessed 2026-10-04
- PrimaryCore Privileged Access Manager (BoKS) datasheet, read in full. Used for the description of BoKS as one centrally managed security domain, the elevated-privilege wording and the regimes it lists.Fortraaccessed 2026-10-04
- PrimaryWindows security event 4769, A Kerberos service ticket was requested, generated on domain controllers. Used for the detection suggestion.Microsoftaccessed 2026-10-04
- Reported byAdvisory AV26-987 of 2 October 2026, which lists boks-server prior to 8.1.0.24 and prior to 9.0.0.7. Used as a cross-check of the fixed builds.Canadian Centre for Cyber Securityaccessed 2026-10-04
- Reported byNews report of 3 October 2026 by Ionut Arghire that pointed us to the advisories. The 'authentication bypass' wording is its own.SecurityWeekaccessed 2026-10-04


