Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    Fortra Patches Critical Vulnerabilities in BoKS

    October 3, 2026

    Alternative Health Influencer Boasts That He’s Been Drinking From a Radioactive Jug for 250 Days Straight

    October 3, 2026

    Samsung Galaxy S25 series receiving One UI 9 stable update in the US

    October 3, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»Fortra Patches Critical Vulnerabilities in BoKS
    Fortra Patches Critical Vulnerabilities in BoKS
    Cybersecurity

    Fortra Patches Critical Vulnerabilities in BoKS

    The Tech GuyBy The Tech GuyOctober 3, 2026No Comments2 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    Fortra has released patches for eight vulnerabilities in Core Privileged Access Manager (BoKS), including three critical-severity bugs.

    Advertisement

    BoKS provides organizations with central management of Unix and Linux fleets, enabling policy enforcement and access control across accounts.

    On Thursday, the company warned that BoKS Manager deployments relying on BoKS keytab for Active Directory service account management are affected by a critical flaw leading to authentication bypass.

    Tracked as CVE-2026-79901 (CVSS score of 9.9), the issue exists because AD service account passwords are generated from a “predictable pseudo-random sequence seeded with the current Unix timestamp.”

    “An attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify candidates offline,” Fortra warned.

    The company underlined that an attacker could exploit the flaw if they knew the affected service principal, could estimate the password-change time, and had suitable Kerberos ticket material.

    Advertisement. Scroll to continue reading.

    “A standard authenticated Active Directory account can ordinarily request a service ticket for an SPN assigned to the affected account; administrative access to BoKS, the service host, or its keytab is not normally required. A previously captured service ticket can alternatively provide offline verification material,” it said.

    The second critical bug, CVE-2026-79898 (CVSS score of 9.1), is a command injection defect in crlserver that could allow an authenticated user to substitute shell commands that would be processed as root on the BoKS Master.

    According to Fortra, the vulnerability is exploitable through BCC and the WSI REST or SOAP API. BCC and WSI can be accessed over the network without a local sudo or suexec rule.

    The company also resolved CVE-2026-12627 (CVSS score of 9.8), a stack buffer overflow in BoKS’s autoregistration functionality that could allow a remote attacker to trigger memory corruption.

    Additionally, Fortra patched five high- and medium-severity BoKS flaws: heap buffer overflows, out-of-bounds read, insecure temporary file, and predictable password generation.

    The company makes no mention of any of these vulnerabilities being exploited in the wild. Additional information can be found on Fortra’s product security page.

    Related: Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks

    Related: Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action

    Related: WatchGuard Patches Critical Fireware OS Code Injection Vulnerability

    Related: Chrome, Firefox Updates Patch Over 100 Vulnerabilities

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    doxx.net Raises $38 Million to Prevent AI Agent-on-the-Internet Misadventures

    October 3, 2026

    In Rare Move, Alleged Iranian State Hacker Extradited to US

    October 3, 2026

    Crypto Scammers Hijack Microsoft’s Official X Account

    October 3, 2026

    macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor

    October 2, 2026

    In Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI Chats

    October 2, 2026

    Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks

    October 2, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 2026392 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 2026211 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202517 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    Fortra Patches Critical Vulnerabilities in BoKS

    October 3, 2026

    Alternative Health Influencer Boasts That He’s Been Drinking From a Radioactive Jug for 250 Days Straight

    October 3, 2026

    Samsung Galaxy S25 series receiving One UI 9 stable update in the US

    October 3, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.