CVE-2026-79896High· 7.5▾ TwilightFortra BoKS Manager contains an out-of-bounds read vulnerability in the custom TLS ClientHello parser used by boks_portmux. A remote unauthenticated attacker can submit a malformed ClientHello and terminate boks_portmux. Although the dae…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Fortra BoKS Manager contains an out-of-bounds read vulnerability in the custom TLS ClientHello parser used by boks_portmux. A remote unauthenticated attacker can submit a malformed ClientHello and terminate boks_portmux. Although the daemon is normally restarted automatically, repeated requests can sustain the service interruption.
boks_manager >= 8.1.0.0 <= 8.1.0.23boks_manager >= 9.0.0.0 <= 9.0.0.6Upgrade to boks-server 8.1.0.24 or boks-server 9.0.0.7.
Until a fixed release is installed, restrict network access to boks_portmux listeners to trusted systems.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-79898Critical· 9.1Fortra BoKS Manager contains a command injection vulnerability in crlserver
CVE-2026-79899High· 7.9Fortra BoKS Manager contains an insecure temporary file vulnerability in bccgethostcert
CVE-2026-12627Critical· 9.8Fortra's Core Privileged Access Manager (BoKS) autoregistration stack buffer overflow vulnerability
CVE-2026-79900Medium· 6.5boks_ksllogsd accepts a checksum algorithm name in the MD field of an authenticated KSL start message
CVE-2026-79901Critical· 9.9In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp
CVE-2025-11494Low· 3.3A vulnerability was found in GNU Binutils 2.45