Fortra disclosed CVE-2026-9862, a critical OS command injection flaw in Core Privileged Access Manager (BoKS) that allows an unauthenticated remote attacker to execute arbitrary commands through the boks_autoregisterd autoregistration service. The vulnerability, tracked in advisory FI-2026-007, affects the BoKS autoregistration functionality exposed on TCP port 6507 by default and was classified as CWE-78 with a CVSS v3.1 vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
Successful exploitation could lead to full system compromise, including data manipulation, service disruption, lateral movement, privilege escalation, and malware deployment, because commands run with the service's privileges. While patches were not yet available at disclosure, Fortra advised organizations to immediately restrict network access to the vulnerable service or disable autoregistration by changing the boksinit configuration on the BoKS Master system.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-9862 was recorded on 2026-06-15 for Fortra Core Privileged Access Manager (BoKS). The entry classifies the issue as CWE-78 and assigns a CVSS v3.1 vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
Fortra publicly disclosed CVE-2026-9862 on 2026-06-15 via advisory FI-2026-007. The flaw allows unauthenticated remote OS command injection in the BoKS autoregistration service, and Fortra recommended restricting network access or disabling autoregistration until patches are available.
Fortra advisory FI-2026-007 states the OS command injection flaw in Core Privileged Access Manager (BoKS) was identified on 2026-05-27. The vulnerability affects the boks_autoregisterd service and can be reached remotely over TCP port 6507 by default.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecvefeed.io
Open sourcefortra.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.