logo

CVE-2026-9862: Fortra BoKS OS Command Injection — CVSS 9.8 RCE

ID: c166fcc7-7cff-52f3-87ae-643d97bb8590

STIX ID: report--c166fcc7-7cff-52f3-87ae-643d97bb8590

Feed Name: CosmicBytez Labs

Threat Score
85/100

Date Published: 2026-06-16

Date Updated: 2026-06-17

...
...

**CVE-2026-9862** is a critical OS command injection in Fortra Core Privileged Access Manager (BoKS) where an unauthenticated remote attacker can inject and execute arbitrary OS commands via the boks_autoregisterd autoregistration service; exploitation yields RCE with service privileges, risks exposure of PAM-managed credentials, and could enable complete network takeover — vendor patches, network restrictions, and monitoring are recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.