CVE-2026-12627Critical· 9.8▾ MidnightFortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow vulnerability in boks_autoregisterd. A remote attacker with network access to the autoregistration service may be able to trigger memory corruption dur…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow vulnerability in boks_autoregisterd. A remote attacker with network access to the autoregistration service may be able to trigger memory corruption during client response processing.
fortra_s_core_privileged_access_manager_boks >= 8.1.0.0 <= 8.1.0.23fortra_s_core_privileged_access_manager_boks >= 9.0.0.0 <= 9.0.0.6Upgrade to boks-server 8.1.0.24 or 9.0.0.7.
Restrict network access to boks_autoregisterd, which listens on port 6507 by default. If autoregistration is not required, disable the boks_autoregisterd service until fixed builds are installed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-79896High· 7.5Fortra BoKS Manager boks_portmux TLS ClientHello out-of-bounds read vulnerability
CVE-2026-79899High· 7.9Fortra BoKS Manager contains an insecure temporary file vulnerability in bccgethostcert
CVE-2026-79898Critical· 9.1Fortra BoKS Manager contains a command injection vulnerability in crlserver
CVE-2026-79900Medium· 6.5boks_ksllogsd accepts a checksum algorithm name in the MD field of an authenticated KSL start message
CVE-2026-79901Critical· 9.9In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp
CVE-2026-15913High· 7.7In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT allows Web Users with both Secure Folders and Secure Mail permissions to escape their sandboxed home directory, achi…