logo

Fortra BoKS Vulnerability Opens Door to Remote Command Injection

ID: afe5e77b-efbc-5f05-be3e-dab31fff3321

STIX ID: report--afe5e77b-efbc-5f05-be3e-dab31fff3321

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-06-17

Date Updated: 2026-06-17

Author: Do Son

...
...

A critical unauthenticated OS command-injection vulnerability (CVE-2026-9862, CVSS 9.8) exists in Fortra BoKS's boks_autoregisterd service, allowing remote attackers with network access to execute arbitrary commands with the service's privileges; the service listens on port 6507 by default. Administrators are advised to immediately restrict network access to port 6507 or disable autoregistration (comment out the autoregisterd line and reload boks_init) and apply vendor patches when released.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.