CVE-2026-9862Disclosure(fortra / core_privileged_access_manager_server)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch fortra core_privileged_access_manager_server systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Fortra's  Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the autoregistration processing.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • core_privileged_access_manager_server

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 2 mentions (2026-06-15); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
core_privileged_access_manager_server

Deep dive

Activity timeline6 mentions / 4d
01122Mentions · 2026-06-15: 2Mentions · 2026-06-16: 1Mentions · 2026-06-17: 2Mentions · 2026-06-19: 1Active Exploitation · 2026-06-15: 1Patch / Workaround · 2026-06-15: 1Patch / Workaround · 2026-06-17: 1Technical Details · 2026-06-15: 1Technical Details · 2026-06-17: 2Technical Details · 2026-06-19: 106-1506-1606-1706-19
Signal classification3 categories
Disclosure
350.0%
General
233.3%
Active Exploitation
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-06-152
Active Exploitation1General1
2026-06-161
General1
2026-06-172
Disclosure2
2026-06-191
Disclosure1
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfortracore_privileged_access_manager_server---

Explore more