search
CVE-2026-9862
Trends
- 1Critical Command Injection Flaw Disclosed in Fortra BoKS Privileged Access Manager▼CVE-2026-9862: Critical OS Command Injection Vulnerability in Fortra BoKS Core Privileged Access Manager Threatens System Security
A critical vulnerability tracked as CVE-2026-9862 has been disclosed in Fortra's BoKS Core Privileged Access Manager, an OS command injection flaw that could let attackers run arbitrary commands on affected systems. Security teams are being urged to patch or restrict exposure, given that privileged access management tools sit at the heart of enterprise infrastructure and a compromise would hand attackers keys to entire environments.
- 2Fortra Patches Command Injection Flaw in BoKS Core PAM●Fortra Patches Command Injection Flaw in BoKS Core PAM Fortra fixed a command injection vulnerability (CVE-2026-9862) in
Fortra has released a fix for a command injection vulnerability, tracked as CVE-2026-9862, in its BoKS Core privileged access management product. The flaw sits in the autoregistration service and allows unauthenticated remote code execution, potentially leading to full system compromise. Security professionals are circulating the advisory and urging administrators to patch affected deployments promptly.