CVE-2026-14316High· 8.1▾ TwilightThe revoked-key error path builds a human-readable failure reason using sprintf() into a heap buffer. The allocated buffer is too small for the final formatted message. When sprintf() writes the full message, it can write past the end of…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
The revoked-key error path builds a human-readable failure reason using sprintf() into a heap buffer. The allocated buffer is too small for the final formatted message. When sprintf() writes the full message, it can write past the end of the heap allocation.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-9864Medium· 4.8Fortra BoKS Server Agent contains a predictable password generation vulnerability in the adjoin utility
CVE-2026-79896High· 7.5Fortra BoKS Manager contains an out-of-bounds read vulnerability in the custom TLS ClientHello parser used by boks_portmux
CVE-2026-12627Critical· 9.8Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow vulnerability in boks_autoregisterd
CVE-2026-79899High· 7.9Fortra BoKS Manager contains an insecure temporary file vulnerability in bccgethostcert
CVE-2026-79898Critical· 9.1Fortra BoKS Manager contains a command injection vulnerability in crlserver
CVE-2026-79900Medium· 6.5boks_ksllogsd accepts a checksum algorithm name in the MD field of an authenticated KSL start message