
Open BoKS autoregistration on 6507 turns a client response into an unauth stack overflow. CVE-2026-12627 (CVSS 9.8) hits Fortra Core PAM before any login. Land 8.1.0.24 or 9.0.0.7, or pull that listener off untrusted nets until the build sticks. https://www.fortra.com/security/advisories/product-security/fi-2026-017
