
Fortra's BoKS generated Active Directory service-account passwords from the clock. Installing the fix secures none of the passwords it already made, and the advisory never says so. No exploitation reported. https://severitydaily.com/fortra-boks-cve-2026-79901-keytab-prng-upgrade-does-not-secure-existing-passwords/
