CVE-2026-9862EPSS p59.1%

CVE-2026-9862CVE-2026-9862

fortra / core_privileged_access_manager_server

Description

Fortra's  Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the autoregistration processing.

Scoring

CVSS 9.8 ()
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS0.99% probability of exploitation · percentile 59.1% · 2026-08-03T12:00:16Z
Last modified2026-07-28
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.